---
id: CVE-2026-57168
title: 'Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER'
summary: >-
  Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:
  CVE-2026-56120. Reason: This candidate is a duplicate of CVE-2026-56120.
  Notes: All CVE users should reference CVE-2026-56120 instead of this
  candidate.
severity: critical
cvss: 9.6
cwe:
  - CWE-639
vendor: openremote
product: 'io.openremote:openremote-manager'
affected:
  - 'io.openremote:openremote-manager < 1.25.0'
patched:
  - 'io.openremote:openremote-manager 1.25.0'
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T23:17:11.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57168'
references:
  - url: >-
      https://github.com/openremote/openremote/security/advisories/GHSA-h3m5-97jq-qjrf
  - url: >-
      https://github.com/openremote/openremote/blob/master/manager/src/main/java/org/openremote/manager/alarm/AlarmResourceImpl.java
  - url: >-
      https://github.com/openremote/openremote/blob/master/manager/src/main/java/org/openremote/manager/alarm/AlarmService.java
  - url: >-
      https://github.com/openremote/openremote/commit/9fad55e5a448c82772d241d395826e5d6fe1ce2d
  - url: 'https://github.com/advisories/GHSA-h3m5-97jq-qjrf'
tags:
  - nvd
  - ghsa
  - maven
aliases:
  - GHSA-h3m5-97jq-qjrf
ecosystem: maven
cvssSource: ghsa
ingestedAt: '2026-07-07T15:41:58.260Z'
---

## Overview

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-56120. Reason: This candidate is a duplicate of CVE-2026-56120. Notes: All CVE users should reference CVE-2026-56120 instead of this candidate.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-57168)

Affected packages:

- `io.openremote:openremote-manager < 1.25.0`

Patched in:

- `io.openremote:openremote-manager 1.25.0`

Source: https://github.com/advisories/GHSA-h3m5-97jq-qjrf
