Skip to content
CVE-2026-66013 - Exploits & Severity

CVE-2026-66013 - Exploits & Severity

Feedly July 25, 2026

OpenRemote before version 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.

An unauthenticated attacker over the network can overwrite push notification tokens and console metadata for any known console asset identifier, redirecting notifications to their own console or preventing legitimate consoles from receiving notifications.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patch available in OpenRemote version 1.26.2 and later

Update OpenRemote to version 1.26.2 or later. Additionally, implement network-level controls to restrict access to the console registration API to trusted networks, and monitor for suspicious console asset registration or updates.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

NVD published the first details for CVE-2026-66013

A CVSS base score of 9.3 has been assigned.

Feedly found the first article mentioning CVE-2026-66013 . See article

GitHub Advisories released a security advisory .

CVE Daily Brief — 2026-07-25

CVE-2026-66013 - Exploits & Severity - Feedly

CVE-2026-66013: OpenRemote before 1.26.2 Authentication Bypass via Console Registration [CRITICAL]

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

Platforms (1)