{"id":"CVE-2026-49439","title":"OpenRemote is an open-source internet-of-things platform","summary":"OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"vendor":"openremote","product":"openremote","affected":["openremote < 1.24.1"],"patched":["io.openremote:openremote-manager 1.24.1"],"published":"2026-09-11","updated":"2026-09-23","sourceUpdated":"2026-09-23T17:17:44.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49439","references":[{"url":"https://github.com/openremote/openremote/commit/583dbbfb96076ba099be8729ddf506acf9e48325","label":"security-advisories@github.com"},{"url":"https://github.com/openremote/openremote/security/advisories/GHSA-xj53-j257-hxvg","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-xj53-j257-hxvg"}],"tags":["nvd","cve.org","ghsa","maven"],"epss":0.00158,"epssPercentile":0.05389,"aliases":["GHSA-xj53-j257-hxvg"],"ecosystem":"maven","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T16:14:50.991165Z"},"ingestedAt":"2026-07-06T17:03:25.189Z","slug":"CVE-2026-49439","body":"## Overview\n\nOpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-49439)\n\nAffected packages:\n\n- `io.openremote:openremote-manager < 1.24.1`\n\nPatched in:\n\n- `io.openremote:openremote-manager 1.24.1`\n\nSource: https://github.com/advisories/GHSA-xj53-j257-hxvg","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}