logo

Critical Authentication Bypass Vulnerability in OpenRemote Disclosed

ID: 1f9f3805-66f1-5644-88d4-f2d63b812d42

STIX ID: report--1f9f3805-66f1-5644-88d4-f2d63b812d42

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-07-26

Date Updated: 2026-07-26

...
...

OpenRemote versions prior to 1.26.2 contain a critical (CVSS 9.3) authentication bypass in the console registration API that lets unauthenticated actors update console assets, overwrite push notification tokens, and alter console metadata—potentially redirecting or blocking notifications. A patch was released in 1.26.2 (published July 25, 2026); immediate updates and network-level access restrictions to the console registration API are recommended. No active exploitation or public PoC has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.