Impact
OpenRemote versions released before 1.26.2 expose a flaw in the console registration API that allows an unauthenticated attacker to supply a known asset identifier and modify existing console assets. The vulnerability, classified as CWE‑639, permits overwriting push‑notification tokens and console metadata without any authentication or ownership checks. This can lead to the hijacking of notification channels or the deliberate denial of service to legitimate consoles.
Affected Systems
All deployments of openremote:openremote that have not applied the 1.26.2 update are affected. The issue is present in every pre‑1.26.2 release of the product, regardless of host configuration.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS score of less than 1 % suggests a low current exploitation probability but still non‑zero. Because no authentication is required to reach the vulnerable endpoint, remote attackers can trigger this flaw from any reachable network location. The vulnerability is not yet listed in the CISA KEV catalog, but the lack of protective controls and the high severity mean that remediation should take priority.
OpenCVE Enrichment