CVE-2026-56784High· 8.1▾ MidnightPoC availableOpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary alarm IDs. The removeAlarms() method in AlarmResourceImpl.java omits realm-scoping validation in its JPA query, enabling any user with alarm-write permissions to enumerate sequential auto-increment alarm IDs and delete cross-tenant alarm records without authorization.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-65009Medium· 4.3OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm
CVE-2026-62238High· 8.8OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL
GHSA-vjr9-f93j-mjr7High· 8.1Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-56120Critical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-57168Critical· 9.6Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER
GHSA-h3m5-97jq-qjrfCritical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)