Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-66013: OpenRemote Console Registration Authentication Bypass

CVE-2026-66013 · published 2 months ago
Summary

OpenRemote before version 1.26.2 allows attackers to update console settings without a password. This can cause notifications to be sent to the wrong consoles or blocked altogether. Update to version 1.26.2 or later to fix this issue.

What to do
  • Update openremote openremote to version 1.26.2 or later.
Affected software
VendorProductAffected versions
openremote openremote < 1.26.2
Original advisory text
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known...
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
Severity
9.3 Critical
CVSS 4.0: 9.3 (NVD)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published25 Jul 2026
Updated27 Sep 2026
First seen25 Jul 2026
Sources
CVE-2026-66013 · MITRE
Track software like this
Free during beta