Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-66013: OpenRemote Console Registration Authentication Bypass

CVE-2026-66013 CVE-2026-66013
Summary

OpenRemote before version 1.26.2 allows attackers to update console settings without a password. This can cause notifications to be sent to the wrong consoles or blocked altogether. Update to version 1.26.2 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
openremote openremote < 1.26.2
Original title
OpenRemote before 1.26.2 Authentication Bypass via Console Registration
Original description
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
nvd CVSS4.0 9.3
Vulnerability type
CWE-639 Authorization Bypass Through User-Controlled Key
Published: 25 Jul 2026 · Updated: 25 Jul 2026 · First seen: 25 Jul 2026