Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-66013: OpenRemote Console Registration Authentication Bypass
CVE-2026-66013
CVE-2026-66013
Summary
OpenRemote before version 1.26.2 allows attackers to update console settings without a password. This can cause notifications to be sent to the wrong consoles or blocked altogether. Update to version 1.26.2 or later to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| openremote | openremote | < 1.26.2 |
Original title
OpenRemote before 1.26.2 Authentication Bypass via Console Registration
Original description
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
nvd CVSS4.0
9.3
Vulnerability type
CWE-639
Authorization Bypass Through User-Controlled Key
Published: 25 Jul 2026 · Updated: 25 Jul 2026 · First seen: 25 Jul 2026