PT-2026-51601 · Unknown · Openremote

·

CVE-2026-56120

·

Published

2026-06-23

·

Updated

2026-06-23

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenRemote versions prior to 1.25.0
Description An insecure direct object reference (IDOR) exists in the bulk alarm deletion endpoint. This occurs because the removeAlarms() function in AlarmResourceImpl.java fails to perform realm-scoping validation in its JPA query. Consequently, authenticated users with alarm-write permissions can delete alarm records belonging to other tenants by providing arbitrary, sequential auto-increment alarm IDs.
Recommendations Update to version 1.25.0 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56120

Affected Products

Openremote