CVE-2026-66013
OpenRemote versions before 1.26.2 have a critical authentication bypass that lets attackers modify console assets without permission. This can overwrite push notification tokens and metadata, redirecting or blocking notifications. The flaw is rated CVSS 9.3.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
OpenRemote platform, versions earlier than 1.26.2, typically used by organizations managing console assets.
Real-world impact
An attacker could change or delete push notification tokens and console metadata, causing legitimate notifications to be misdirected or lost, and potentially enabling further compromise of the console.
Why this severity
The CVSS score of 9.3 reflects a high impact on confidentiality and integrity (high vulnerability and impact) combined with low attack complexity and no user interaction, meaning anyone on the network can exploit it easily.
What to do about it
- 011. Verify the current OpenRemote version.
- 022. If the version is older than 1.26.2, download and install OpenRemote 1.26.2 or later.
- 033. Restart the OpenRemote service to apply the update.
NVD description
Timeline
- Jul 25, 2026 · 7d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 25, 2026 · 7d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.