Description
OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.
Published: 2026-09-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Permission bypass
Action: Patch
AI Analysis

Impact

OpenRemote, an open‑source IoT platform, contains a flaw in the predicted datapoint write endpoint. Prior to version 1.24.1, users who only possess `read:assets` privileges can send HTTP requests to create or modify predicted datapoints. This improper authorization (CWE‑862) lets a non‑privileged user alter forecast data that should be immutable, undermining the integrity of device telemetry and potentially leading to incorrect device behavior or misleading analytics. Version 1.24.1 fixes the issue.

Affected Systems

The issue affects all OpenRemote installations with versions earlier than 1.24.1. The vulnerable component is the predicted datapoint write API exposed through the OpenRemote web service. Versions 1.24.1 and later incorporate the authorization fix described in the commit on 583dbbfb96… .

Risk and Exploitability

The CVSS base score of 4.3 indicates a low‑to‑moderate severity, reflecting that a successful exploit would mainly affect data integrity rather than confidentiality or availability. The EPSS score is reported as less than 1 %, signaling a very low probability of active exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits have been reported. An attacker would need valid authentication with read‑only asset permissions and would target the exposed HTTP endpoint to write predicted datapoints, effectively bypassing proper authorization controls. Overall, the risk is moderate but constrained by the low exploitation likelihood and absence of known attacks.

Generated by OpenCVE AI on September 15, 2026 at 19:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Follow the vendor advisories and upgrade OpenRemote to version 1.24.1 or newer, which includes the authorization fix.
  • If an upgrade cannot be performed immediately, restrict write access to the predicted datapoint API to a trusted network segment or whitelist known IP addresses.
  • Monitor and log write attempts on predicted datapoints to detect unauthorized activity, and review any anomalies in forecast data.

Generated by OpenCVE AI on September 15, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xj53-j257-hxvg OpenRemote read-only asset users can write predicted datapoints
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Openremote
Openremote openremote
Vendors & Products Openremote
Openremote openremote

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.
Title OpenRemote read-only asset users can write predicted datapoints
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Openremote Openremote
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:17:52.256Z

Reserved: 2026-05-30T02:43:33.105Z

Link: CVE-2026-49439

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:52.167Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T21:17:10.370

Modified: 2026-09-23T17:17:44.217

Link: CVE-2026-49439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses