CVE-2026-66013
OpenRemote before 1.26.2 Authentication Bypass via Console Registration
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
| CWE | CWE-639 |
| Vendor | openremote |
| Product | openremote |
| Published | Jul 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for openremote openremote
Be the first to know when new unknown vulnerabilities affecting openremote openremote are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
openremote / openremote
0 < 1.26.2
References
Credits
๐ aramosf