Cross-Realm Information Disclosure in OpenRemote by OpenRemote
CVE-2026-81679

8.3HIGH

Key Information:

Vendor

Openremote

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81679?

OpenRemote versions prior to 1.28.0 are susceptible to a cross-realm information disclosure vulnerability within the Notification REST API. This issue enables per-realm tenant administrators to gain unauthorized access to sensitive notifications, including message bodies, from all tenants. Attackers possessing read:admin credentials in one realm can issue a zero-parameter GET request to the notification endpoint, effectively retrieving private notification metadata and message content across multiple realms. This flaw significantly compromises tenant data security and necessitates prompt mitigation.

Affected Version(s)

openremote 0 < 1.28.0

openremote 1.28.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.