Authentication Bypass in OpenRemote Console Registration API by OpenRemote
CVE-2026-66013
9.3CRITICAL
What is CVE-2026-66013?
The OpenRemote platform prior to version 1.26.2 is impacted by a significant security vulnerability that allows unauthorized access through the console registration API. This flaw enables attackers to manipulate existing console assets without any form of authentication, simply by providing valid asset identifiers. Such actions can lead to the overwrite of push notification tokens and console metadata, effectively granting malicious actors the power to redirect notifications, potentially denying delivery to legitimate consoles. This could result in severe consequences for users relying on OpenRemote for secure operations, emphasizing the urgent need for version updates to mitigate these risks.
Affected Version(s)
openremote 0 < 1.26.2
openremote 1.26.2
