exploit-intel.com
Critical Authentication Bypass Vulnerability in OpenRemote Disclosed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
OpenRemote versions prior to 1.26.2 have been found to contain an authentication bypass vulnerability in the console registration API. This flaw allows unauthenticated attackers to update existing console assets by providing a known asset identifier. Attackers can overwrite push notification tokens and console metadata, potentially redirecting notifications or preventing legitimate consoles from receiving them. The vulnerability has been assigned a CVSS base score of 9.3, indicating a critical severity level. Currently, there is no evidence of active exploitation or public proof-of-concept available. A patch has been released in version 1.26.2, and users are advised to update immediately. Network-level controls should also be implemented to restrict access to the console registration API. The vulnerability was first published on July 25, 2026.
Key Points: • OpenRemote before version 1.26.2 is vulnerable to an authentication bypass. • Attackers can exploit this flaw to redirect notifications or block legitimate delivery. • A critical patch is available in version 1.26.2; immediate updates are recommended.