Vulnary
← back to the feed
Critical· 9.3official fix available

CVE-2026-66013

OpenRemote versions before 1.26.2 have a critical authentication bypass that lets attackers modify console assets without permission. This can overwrite push notification tokens and metadata, redirecting or blocking notifications. The flaw is rated CVSS 9.3.

publishedJul 25, 2026
last modifiedJul 30, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
32th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 24, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

OpenRemote platform, versions earlier than 1.26.2, typically used by organizations managing console assets.

02

Real-world impact

An attacker could change or delete push notification tokens and console metadata, causing legitimate notifications to be misdirected or lost, and potentially enabling further compromise of the console.

03

Why this severity

The CVSS score of 9.3 reflects a high impact on confidentiality and integrity (high vulnerability and impact) combined with low attack complexity and no user interaction, meaning anyone on the network can exploit it easily.

04

What to do about it

official fix available
recommended steps
  1. 011. Verify the current OpenRemote version.
  2. 022. If the version is older than 1.26.2, download and install OpenRemote 1.26.2 or later.
  3. 033. Restart the OpenRemote service to apply the update.

NVD description

05

Timeline

  1. Jul 25, 2026 · 7d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 25, 2026 · 7d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
  3. Jul 30, 2026 · 1d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactLow
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-66013: OpenRemote versions before 1.26.2 have a critical authentication bypas · Vulnary