---
id: CVE-2026-62238
title: >-
  OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability
  in the datapoint crosstab export endpoint that constructs PostgreSQL queries
  by concatenating asset display names into raw SQL
summary: >-
  OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability
  in the datapoint crosstab export endpoint that constructs PostgreSQL queries
  by concatenating asset display names into raw SQL. An authenticated attacker
  with …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: openremote
product: openremote
affected:
  - openremote < 1.26.0
patched:
  - openremote 1.26.0
published: '2026-07-17'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:27.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-62238'
references:
  - url: >-
      https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7v
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openremote-sql-injection-via-crosstab-export
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7v
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-17T10:28:06.337245Z'
scores:
  nvd: 8.8
  cna: 7.2
epss: 0.00498
epssPercentile: 0.40698
ingestedAt: '2026-10-08T16:52:14.703Z'
---

## Overview

OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration.

## Affected

- `openremote < 1.26.0`

## Remediation

Upgrade past the affected range:

- `openremote 1.26.0`
