Insecure Direct Object Reference in OpenRemote Product by OpenRemote
CVE-2026-67310

5.3MEDIUM

Key Information:

Vendor

Openremote

Vendor
CVE Published:
1 August 2026

What is CVE-2026-67310?

OpenRemote versions prior to 1.27.0 are susceptible to an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. This flaw arises from a realm access check that fails to validate all realms, instead processing only a single realm derived from a HashSet. As the order of HashSet iteration is non-deterministic, an authenticated attacker can exploit this by manipulating alarm-asset links from both their own and a victim's realm. This results in a potential cross-tenant disclosure of victim asset names during GET requests on the attacker's own alarm, with a chance of successful exploitation in multiple requests. The vulnerability has been addressed in version 1.27.0.

Affected Version(s)

openremote 0 < 1.27.0

openremote 1.27.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.