Authentication Bypass in OpenRemote Console Registration API by OpenRemote
CVE-2026-66013

9.3CRITICAL

Key Information:

Vendor

Openremote

Vendor
CVE Published:
25 July 2026

What is CVE-2026-66013?

The OpenRemote platform prior to version 1.26.2 is impacted by a significant security vulnerability that allows unauthorized access through the console registration API. This flaw enables attackers to manipulate existing console assets without any form of authentication, simply by providing valid asset identifiers. Such actions can lead to the overwrite of push notification tokens and console metadata, effectively granting malicious actors the power to redirect notifications, potentially denying delivery to legitimate consoles. This could result in severe consequences for users relying on OpenRemote for secure operations, emphasizing the urgent need for version updates to mitigate these risks.

Affected Version(s)

openremote 0 < 1.26.2

openremote 1.26.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

aramosf
.