๐Ÿ” CVE Alert

CVE-2026-66013

UNKNOWN 0.0

OpenRemote before 1.26.2 Authentication Bypass via Console Registration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.

CWE CWE-639
Vendor openremote
Product openremote
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for openremote openremote

Be the first to know when new unknown vulnerabilities affecting openremote openremote are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openremote / openremote
0 < 1.26.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openremote/openremote/security/advisories/GHSA-gpfc-h59v-63cv vulncheck.com: https://www.vulncheck.com/advisories/openremote-before-authentication-bypass-via-console-registration

Credits

๐Ÿ” aramosf