Cross-Realm Notification Deletion in OpenRemote by OpenRemote
CVE-2026-73616

7.1HIGH

Key Information:

Vendor

Openremote

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73616?

The OpenRemote Notification System contains a vulnerability where the notification deletion endpoints do not adequately enforce realm boundaries. This flaw enables realm administrators to delete notifications that do not belong to their realm. Specifically, an attacker with the write:admin role can exploit this oversight by sending DELETE requests to remove notifications from other realms and the master realm without appropriate authorization checks in place. This could lead to unauthorized data manipulation and compromise the integrity of notifications across multiple realms.

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
.