VulnSea

openremote has 6 CVEs on record. Disclosure cadence is accelerating: 4 in the last 90 days against 2 in the 90 before. The busiest recent month was July 2026 with 3. The median CVSS is 7.7 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-639 (3). Most affected products: io.openremote:openremote-manager (4), io.openremote:openremote-agent (1), openremote (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.7
Publish → KEV
Last 90 days
4 prev 2

Products

  • io.openremote:openremote-manager 4
  • io.openremote:openremote-agent 1
  • openremote 1
6
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

openremote vulnerabilities

CVEs affecting openremote, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-49439Medium· 4.3
1w ago

OpenRemote is an open-source internet-of-things platform

OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.

Sunlitopenremote · openremoteEPSS 0.16%via NVD
GHSA-cgfv-jrfp-2r7vHigh
2mo ago

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

Twilightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-54641High· 7.7
2mo ago

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

Twilightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-54640High· 7.6
2mo ago

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory

OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory

Twilightopenremote · io.openremote:openremote-agentvia GHSA
CVE-2026-57168Critical· 9.6
3mo ago

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

Midnightopenremote · io.openremote:openremote-managervia GHSA
GHSA-h3m5-97jq-qjrfCritical· 9.6
3mo ago

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

Midnightopenremote · io.openremote:openremote-managervia GHSA
openremote vulnerabilities (CVEs) · VulnSea