Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-66013: OpenRemote Console Registration Authentication Bypass
CVE-2026-66013 · published 2 months ago
Summary
OpenRemote before version 1.26.2 allows attackers to update console settings without a password. This can cause notifications to be sent to the wrong consoles or blocked altogether. Update to version 1.26.2 or later to fix this issue.
What to do
- Update openremote openremote to version 1.26.2 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| openremote | openremote | < 1.26.2 |
Original advisory text
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known...
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
References
- https://github.com/openremote/openremote/security/advisories/GHSA-gpfc-h59v-63cv
- https://www.vulncheck.com/advisories/openremote-before-authentication-bypass-via...
- https://nvd.nist.gov/vuln/detail/CVE-2026-66013 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66013... Vendor Advisory
Severity
9.3
Critical
CVSS 4.0: 9.3 (NVD)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published25 Jul 2026
Updated27 Sep 2026
First seen25 Jul 2026
Track software like this
Free during beta