CVE-2026-66013
openremote · openremote
OpenRemote before 1.26.2 contains an authentication bypass in the console registration API, allowing unauthenticated attackers to overwrite console metadata and push notification tokens.
Executive summary
An authentication bypass vulnerability in OpenRemote allows unauthenticated attackers to manipulate console assets, leading to potential denial of service or unauthorized redirection of notifications.
Vulnerability
The vulnerability exists in the console registration API, which fails to properly validate ownership of assets during update requests. This allows an unauthenticated attacker to supply a known identifier and overwrite critical console metadata.
Business impact
Successful exploitation allows an attacker to disrupt service delivery by overwriting push notification tokens or redirecting traffic. While the vulnerability does not provide full system access, the CVSS score of 9.3 highlights the significant risk to operational integrity and availability of the OpenRemote platform.
Remediation
Immediate Action: Update openremote openremote to version 1.26.2 or later to enforce proper authentication during the console registration process.
Proactive Monitoring: Monitor logs for unauthorized or suspicious calls to the console registration API, particularly those originating from unknown or unexpected sources.
Compensating Controls: Implement network-level access controls to limit access to the registration API to known, trusted management segments.
Exploitation status
Public Exploit Available: No (no confirmed public exploit exists in available data).
Analyst recommendation
The high severity of this authentication bypass necessitates an immediate update to the latest version. Failure to patch may result in service disruption and loss of control over console assets.