exploit-intel.com Critical Authentication Bypass Vulnerability in OpenRemote Disclosed
Article Content
- •OpenRemote before version 1.26.2 is vulnerable to an authentication bypass.
- •Attackers can exploit this flaw to redirect notifications or block legitimate delivery.
- •A critical patch is available in version 1.26.2; immediate updates are recommended.
OpenRemote versions prior to 1.26.2 have been found to contain an authentication bypass vulnerability in the console registration API. This flaw allows unauthenticated attackers to update existing console assets by providing a known asset identifier. Attackers can overwrite push notification tokens and console metadata, potentially redirecting notifications or preventing legitimate consoles from receiving them. The vulnerability has been assigned a CVSS base score of 9.3, indicating a critical severity level. Currently, there is no evidence of active exploitation or public proof-of-concept available. A patch has been released in version 1.26.2, and users are advised to update immediately. Network-level controls should also be implemented to restrict access to the console registration API. The vulnerability was first published on July 25, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-66013 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…