Insecure Direct Object Reference in OpenRemote Product by OpenRemote
CVE-2026-67310
What is CVE-2026-67310?
OpenRemote versions prior to 1.27.0 are susceptible to an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. This flaw arises from a realm access check that fails to validate all realms, instead processing only a single realm derived from a HashSet. As the order of HashSet iteration is non-deterministic, an authenticated attacker can exploit this by manipulating alarm-asset links from both their own and a victim's realm. This results in a potential cross-tenant disclosure of victim asset names during GET requests on the attacker's own alarm, with a chance of successful exploitation in multiple requests. The vulnerability has been addressed in version 1.27.0.
Affected Version(s)
openremote 0 < 1.27.0
openremote 1.27.0
