openremote has 6 CVEs on record. Disclosure cadence is accelerating: 4 in the last 90 days against 2 in the 90 before. The busiest recent month was July 2026 with 3. The median CVSS is 7.7 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-639 (3). Most affected products: io.openremote:openremote-manager (4), io.openremote:openremote-agent (1), openremote (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 4 prev 2
Products
- io.openremote:openremote-manager 4
- io.openremote:openremote-agent 1
- openremote 1
Worst active — by depth score
GHSA-h3m5-97jq-qjrfCritical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)53CVE-2026-57168Critical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)53CVE-2026-54641High· 7.7OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl42CVE-2026-54640High· 7.6OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory42GHSA-cgfv-jrfp-2r7vHighOpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export41
openremote vulnerabilities
CVEs affecting openremote, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-49439Medium· 4.3OpenRemote is an open-source internet-of-things platform
OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.
GHSA-cgfv-jrfp-2r7vHighOpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
CVE-2026-54641High· 7.7OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
CVE-2026-54640High· 7.6OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
CVE-2026-57168Critical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
GHSA-h3m5-97jq-qjrfCritical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)