Cross-Realm Information Disclosure in OpenRemote by OpenRemote
CVE-2026-81679
8.3HIGH
What is CVE-2026-81679?
OpenRemote versions prior to 1.28.0 are susceptible to a cross-realm information disclosure vulnerability within the Notification REST API. This issue enables per-realm tenant administrators to gain unauthorized access to sensitive notifications, including message bodies, from all tenants. Attackers possessing read:admin credentials in one realm can issue a zero-parameter GET request to the notification endpoint, effectively retrieving private notification metadata and message content across multiple realms. This flaw significantly compromises tenant data security and necessitates prompt mitigation.
Affected Version(s)
openremote 0 < 1.28.0
openremote 1.28.0
