Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Aramosf

#15827of 56,330
18.1Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-64763
9.3
2026-07-25
Unknown · Openremote · CVE-2026-66013
**Name of the Vulnerable Software and Affected Versions** OpenRemote versions prior to 1.26.2 **Description** An authentication bypass exists in the console registration API. Unauthenticated attackers can update existing console assets by providing a known asset identifier. This allows the overwriting of push notification tokens and console metadata without ownership validation, which can lead to the redirection of notifications or the denial of delivery to legitimate consoles. **Recommendations** Update to version 1.26.2 or later.
PT-2026-60648
8.8
2026-07-06
Unknown · Openremote · CVE-2026-62238
**Name of the Vulnerable Software and Affected Versions** OpenRemote versions prior to 1.26.0 **Description** An authenticated user with permissions to create or rename assets can perform a SQL injection. The issue occurs at the datapoint crosstab export endpoint, which builds PostgreSQL queries by concatenating asset display names directly into raw SQL. By manipulating the `asset name` parameter, an attacker can execute arbitrary SQL commands and exfiltrate database information via the exported CSV response. **Recommendations** Update to version 1.26.0 or later.