PT-2026-82580 · Unknown · Openremote

·

CVE-2026-81679

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenRemote versions prior to 1.28.0
Description A cross-realm information disclosure issue exists in the Notification REST API. Tenant administrators with read:admin credentials in a single realm can retrieve sensitive notification metadata and message bodies from all other realms by submitting a zero-parameter GET request to the notification endpoint.
Recommendations Update to version 1.28.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81679
GHSA-6FF4-4FRC-R287

Affected Products

Openremote