NONE · 0

CVE-2026-66013

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known as...

Vulnerability Description

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-66013?

CVE-2026-66013 is a documented vulnerability. OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known as...

How severe is CVE-2026-66013?

CVSS scoring is not yet available for CVE-2026-66013. Check NVD for updates.

Is there a patch for CVE-2026-66013?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.