logo

IoT Under Fire: Critical CVSS 10 Expression Injection Hits OpenRemote Platform

ID: 7d73819b-16f0-55e5-8e8c-017b6c5096c5

STIX ID: report--7d73819b-16f0-55e5-8e8c-017b6c5096c5

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

OpenRemote disclosed CVE-2026-39842 (CVSS 10) — critical expression-injection vulnerabilities in its JavaScript (Nashorn) and Groovy rules engines that allow arbitrary server-side code execution and potential full takeover of IoT environments; the issues stem from lack of sandboxing, missing class filtering, and an unregistered Groovy DenyAllFilter, and administrators are urged to upgrade to version 1.22.0 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.