Description
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
Published: 2026-07-25
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenRemote versions released before 1.26.2 expose a flaw in the console registration API that allows an unauthenticated attacker to supply a known asset identifier and modify existing console assets. The vulnerability, classified as CWE‑639, permits overwriting push‑notification tokens and console metadata without any authentication or ownership checks. This can lead to the hijacking of notification channels or the deliberate denial of service to legitimate consoles.

Affected Systems

All deployments of openremote:openremote that have not applied the 1.26.2 update are affected. The issue is present in every pre‑1.26.2 release of the product, regardless of host configuration.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, while the EPSS score of less than 1 % suggests a low current exploitation probability but still non‑zero. Because no authentication is required to reach the vulnerable endpoint, remote attackers can trigger this flaw from any reachable network location. The vulnerability is not yet listed in the CISA KEV catalog, but the lack of protective controls and the high severity mean that remediation should take priority.

Generated by OpenCVE AI on August 3, 2026 at 18:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenRemote to 1.26.2 or later to apply the vendor fix.
  • If upgrading is not immediately possible, block unauthenticated traffic to the console registration API with a firewall or behind a reverse‑proxy that requires authentication.
  • As a temporary measure, modify the console registration endpoint to reject any request that attempts to change push‑notification tokens or console metadata unless the request includes a valid authentication token and ownership verification.

Generated by OpenCVE AI on August 3, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 25 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Description OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
Title OpenRemote before 1.26.2 Authentication Bypass via Console Registration
First Time appeared Openremote
Openremote openremote
Weaknesses CWE-639
CPEs cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:*
Vendors & Products Openremote
Openremote openremote
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Openremote Openremote
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-29T19:26:42.479Z

Reserved: 2026-07-23T19:22:30.643Z

Link: CVE-2026-66013

cve-icon Vulnrichment

Updated: 2026-07-27T15:54:53.845Z

cve-icon NVD

Status : Deferred

Published: 2026-07-25T11:17:19.193

Modified: 2026-07-30T20:11:09.180

Link: CVE-2026-66013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:30:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key