PT-2026-82580 · Unknown · Openremote
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenRemote versions prior to 1.28.0
Description
A cross-realm information disclosure issue exists in the Notification REST API. Tenant administrators with
read:admin credentials in a single realm can retrieve sensitive notification metadata and message bodies from all other realms by submitting a zero-parameter GET request to the notification endpoint.Recommendations
Update to version 1.28.0 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openremote