Critical Authentication Bypass Vulnerability in OpenRemote Disclosed

Critical Authentication Bypass Vulnerability in OpenRemote Disclosed

First seen 26 Jul 2026, 18:04 UTC Feedlywww.incibe.esexploit-intel.comeuvd.enisa.europa.eu 89% similarity 72.9

Article Content

Browse articles
ThreatCluster

OpenRemote versions prior to 1.26.2 have been found to contain an authentication bypass vulnerability in the console registration API. This flaw allows unauthenticated attackers to update existing console assets by providing a known asset identifier. Attackers can overwrite push notification tokens and console metadata, potentially redirecting notifications or preventing legitimate consoles from receiving them. The vulnerability has been assigned a CVSS base score of 9.3, indicating a critical severity level. Currently, there is no evidence of active exploitation or public proof-of-concept available. A patch has been released in version 1.26.2, and users are advised to update immediately. Network-level controls should also be implemented to restrict access to the console registration API. The vulnerability was first published on July 25, 2026.

Key Points: • OpenRemote before version 1.26.2 is vulnerable to an authentication bypass. • Attackers can exploit this flaw to redirect notifications or block legitimate delivery. • A critical patch is available in version 1.26.2; immediate updates are recommended.

ThreatCluster AI

Timeline

2026-07-25
CVE-2026-66013 published
The authentication bypass vulnerability in OpenRemote was officially disclosed, with a CVSS score of 9.3.
Feedly
2026-07-26
Vulnerability confirmed by INCIBE-CERT
INCIBE-CERT confirmed the authentication bypass vulnerability and its impact on OpenRemote before version 1.26.2.
www.incibe.es
2026-07-26
Exploit Intelligence reports on vulnerability
Exploit Intelligence highlighted the critical nature of the authentication bypass vulnerability in OpenRemote.
exploit-intel.com

Community

Browse all →