Skip to content
Critical Authentication Bypass Vulnerability in OpenRemote Disclosed

Critical Authentication Bypass Vulnerability in OpenRemote Disclosed

First seen 26 Jul 2026, 18:04 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 27, 2026 at 16:11 UTC
  • OpenRemote before version 1.26.2 is vulnerable to an authentication bypass.
  • Attackers can exploit this flaw to redirect notifications or block legitimate delivery.
  • A critical patch is available in version 1.26.2; immediate updates are recommended.

OpenRemote versions prior to 1.26.2 have been found to contain an authentication bypass vulnerability in the console registration API. This flaw allows unauthenticated attackers to update existing console assets by providing a known asset identifier. Attackers can overwrite push notification tokens and console metadata, potentially redirecting notifications or preventing legitimate consoles from receiving them. The vulnerability has been assigned a CVSS base score of 9.3, indicating a critical severity level. Currently, there is no evidence of active exploitation or public proof-of-concept available. A patch has been released in version 1.26.2, and users are advised to update immediately. Network-level controls should also be implemented to restrict access to the console registration API. The vulnerability was first published on July 25, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 55d ago How this analysis works

Timeline

2026-07-25
CVE-2026-66013 published
The authentication bypass vulnerability in OpenRemote was officially disclosed, with a CVSS score of 9.3.
Feedly
2026-07-26
Vulnerability confirmed by INCIBE-CERT
INCIBE-CERT confirmed the authentication bypass vulnerability and its impact on OpenRemote before version 1.26.2.
www.incibe.es
2026-07-26
Exploit Intelligence reports on vulnerability
Exploit Intelligence highlighted the critical nature of the authentication bypass vulnerability in OpenRemote.
exploit-intel.com

More articles in this cluster (4)

Following this threat?

Track CVE-2026-66013 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed