Impact
The vulnerability allows a realm administrator who possesses a write:admin role to delete notifications belonging to other realms, including the master realm or other tenants. Because the notification deletion endpoints fail to enforce realm boundaries, an attacker can compromise the integrity of data by removing legitimate notifications. This flaw enables deletion of business-critical alerts and communications, potentially disrupting operations and erasing audit trail information, but does not provide direct access to other data sets or system control.
Affected Systems
The OpenRemote platform is impacted, with affected releases ranging from 1.13.1 through 1.22.1. All listed versions identified by the CNA are vulnerable to the cross‑realm insecure direct object reference flaw in the notification deletion functionality.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact likelihood. The EPSS score is not available, and the flaw is not currently listed in the CISA KEV catalog. Attackers need only possess a write:admin role within a realm and can issue DELETE requests against the notification endpoint to affect other realms – the vulnerability is exploitable over the network or via the internal application interface. Because the flaw arises from missing access control checks, it can be triggered by legitimate administrative users who are mis‑directed or by malicious actors inserted into the realm administration role.
OpenCVE Enrichment