CVE-2026-66013
Vulnerability Description
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-639
Source
NVD
Vendor
openremote
Product
openremote
Discussion (0)
Add Comment
No comments yet. Be the first!