Cross-Realm Notification Deletion in OpenRemote by OpenRemote
CVE-2026-73616
7.1HIGH
What is CVE-2026-73616?
The OpenRemote Notification System contains a vulnerability where the notification deletion endpoints do not adequately enforce realm boundaries. This flaw enables realm administrators to delete notifications that do not belong to their realm. Specifically, an attacker with the write:admin role can exploit this oversight by sending DELETE requests to remove notifications from other realms and the master realm without appropriate authorization checks in place. This could lead to unauthorized data manipulation and compromise the integrity of notifications across multiple realms.
