CVE-2026-57168Critical· 9.6▾ MidnightRejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-56120. Reason: This candidate is a duplicate of CVE-2026-56120. Notes: All CVE users should reference CVE-2026-56120 instead of this candidate.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-56120. Reason: This candidate is a duplicate of CVE-2026-56120. Notes: All CVE users should reference CVE-2026-56120 instead of this candidate.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
io.openremote:openremote-manager < 1.25.0Patched in:
io.openremote:openremote-manager 1.25.0Connected by shared product, vendor, weakness, or advisory.
GHSA-h3m5-97jq-qjrfCritical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-54641High· 7.7OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
GHSA-cgfv-jrfp-2r7vHighOpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2026-54640High· 7.6OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
CVE-2026-49439Medium· 4.3OpenRemote is an open-source internet-of-things platform