Information Disclosure in OpenRemote REST API
CVE-2026-65009

5.3MEDIUM

Key Information:

Vendor

Openremote

Vendor
CVE Published:
21 July 2026

What is CVE-2026-65009?

OpenRemote versions prior to 1.26.2 are affected by an information disclosure vulnerability allowing attackers with the read:rules role to access sensitive operational logs via the SyslogResource REST endpoint. This vulnerability permits unauthorized retrieval of operational logs, including asset IDs, agent connection details, rule names, and protocol errors, from all tenants within a multi-tenant deployment. Organizations using affected versions should ensure prompt updates to safeguard against potential data exposure.

Affected Version(s)

openremote 0 < 1.26.2

openremote 1.26.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.