Critical Authentication Bypass Vulnerability in OpenRemote Disclosed
ID: 1f9f3805-66f1-5644-88d4-f2d63b812d42
STIX ID: report--1f9f3805-66f1-5644-88d4-f2d63b812d42
Feed Name: ThreatCluster
OpenRemote versions prior to 1.26.2 contain a critical (CVSS 9.3) authentication bypass in the console registration API that lets unauthenticated actors update console assets, overwrite push notification tokens, and alter console metadata—potentially redirecting or blocking notifications. A patch was released in 1.26.2 (published July 25, 2026); immediate updates and network-level access restrictions to the console registration API are recommended. No active exploitation or public PoC has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
