---
id: CVE-2026-56784
title: >-
  OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR)
  vulnerability in the bulk alarm deletion endpoint that allows authenticated
  users to permanently delete alarms belonging to other tenants by supplying
  arbitrary…
summary: >-
  OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR)
  vulnerability in the bulk alarm deletion endpoint that allows authenticated
  users to permanently delete alarms belonging to other tenants by supplying
  arbitrary…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-639
vendor: openremote
product: openremote
affected:
  - openremote < 1.25.0
published: '2026-06-23'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:22.700'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56784'
references:
  - url: >-
      https://github.com/openremote/openremote/security/advisories/GHSA-h3m5-97jq-qjrf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openremote-cross-tenant-idor-in-bulk-alarm-deletion
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openremote/openremote/security/advisories/GHSA-h3m5-97jq-qjrf
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-23T15:02:05.383363Z'
epss: 0.00363
epssPercentile: 0.28073
ingestedAt: '2026-10-08T16:52:14.693Z'
---

## Overview

OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary alarm IDs. The removeAlarms() method in AlarmResourceImpl.java omits realm-scoping validation in its JPA query, enabling any user with alarm-write permissions to enumerate sequential auto-increment alarm IDs and delete cross-tenant alarm records without authorization.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
