Vulnerability Description
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/openremote/openremote/security/advisories/GHSA-rc23-4mmm-4fx9
- https://www.vulncheck.com/advisories/openremote-notification-delete-cross-realm-
- https://github.com/openremote/openremote/security/advisories/GHSA-rc23-4mmm-4fx9
FAQ
What is CVE-2026-73616?
CVE-2026-73616 is a vulnerability with a CVSS score of 6.5 (MEDIUM). OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one ...
How severe is CVE-2026-73616?
CVE-2026-73616 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73616?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.