IoT Under Fire: Critical CVSS 10 Expression Injection Hits OpenRemote Platform
ID: 7d73819b-16f0-55e5-8e8c-017b6c5096c5
STIX ID: report--7d73819b-16f0-55e5-8e8c-017b6c5096c5
Feed Name: securityonline.info
Threat Score
OpenRemote disclosed CVE-2026-39842 (CVSS 10) — critical expression-injection vulnerabilities in its JavaScript (Nashorn) and Groovy rules engines that allow arbitrary server-side code execution and potential full takeover of IoT environments; the issues stem from lack of sandboxing, missing class filtering, and an unregistered Groovy DenyAllFilter, and administrators are urged to upgrade to version 1.22.0 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
