Impact
The vulnerability is a cross‑realm information disclosure in the Notification REST API. An attacker who has read:admin privileges in one tenant realm can perform a zero‑parameter GET request to the notification endpoint and retrieve the entire set of sent notifications, including message bodies, for all realms. This results in a confidentiality breach where sensitive messages are exposed beyond their intended tenant boundaries, exactly matching the definition of CWE‑200.
Affected Systems
The affected product is OpenRemote, all releases before version 1.28.0. The advisory lists the vendor openremote:openremote and no further sub‑products. The disclosure applies to every tenant within installations of these versions, because the notification API is shared across realms.
Risk and Exploitability
The CVSS v3.1 score of 8.3 indicates high severity. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits are known. Attackers can exploit the vulnerability remotely by issuing a simple HTTPS GET request to the /notification endpoint; no additional authentication beyond read:admin is required. Because the payloads are readable even without specialized payloads, the risk of exploitation is moderate to high, especially in environments where tenant administrators have broad permissions. Prompt remediation reduces the potential for widespread sensitive data leakage.
OpenCVE Enrichment