openremote
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 8
en
Verify to analyze this security profile
As of 09/19/2026, openremote recorded 8 security vulnerabilities in the last 90 days across 1 products, including 5 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, openremote had the most security vulnerabilities in the openremote ecosystem, with 8 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-49439OpenRemote read-only asset users can write predicted datapoints | Exploitation statusNot confirmed | FixNot confirmed | Affected productopenremote | Published09/11/2026 | SeverityMedium |
CVE-2026-81679OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API | Exploitation statusNot known exploited | FixYes | Affected productopenremote | Published08/27/2026 | SeverityHigh |
CVE-2026-73616OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference | Exploitation statusPublic exploit | FixNot confirmed | Affected productopenremote | Published08/13/2026 | SeverityHigh |
CVE-2026-67310openremote before 1.27.0 Cross-Tenant IDOR via setAssetLinks | Exploitation statusNot known exploited | FixYes | Affected productopenremote | Published08/01/2026 | SeverityMedium |
CVE-2026-66013OpenRemote before 1.26.2 Authentication Bypass via Console Registration | Exploitation statusNot known exploited | FixYes | Affected productopenremote | Published07/25/2026 | SeverityCritical |
CVE-2026-65009OpenRemote before 1.26.2 Information Disclosure via Syslog REST API | Exploitation statusPublic exploit | FixYes | Affected productopenremote | Published07/21/2026 | SeverityMedium |
CVE-2026-62238OpenRemote < 1.26.0 SQL Injection via Crosstab Export | Exploitation statusPublic exploit | FixYes | Affected productopenremote | Published07/17/2026 | SeverityHigh |
CVE-2026-56120 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published06/23/2026 | SeverityUnknown |
CVE-2026-56784OpenRemote < 1.25.0 IDOR via Bulk Alarm Deletion Endpoint | Exploitation statusPublic exploit | FixYes | Affected productopenremote | Published06/23/2026 | SeverityHigh |
CVE-2026-40882OpenRemote has XXE in Velbus Asset Import | Exploitation statusPublic exploit | FixNot confirmed | Affected productopenremote | Published04/22/2026 | SeverityHigh |
CVE-2026-41166OpenRemote has Improper Access Control via updateUserRealmRoles function | Exploitation statusPublic exploit | FixNot confirmed | Affected productopenremote | Published04/22/2026 | SeverityHigh |
CVE-2026-39842OpenRemote is Vulnerable to Expression Injection | Exploitation statusPublic exploit | FixYes | Affected productopenremote | Published04/14/2026 | SeverityCritical |
CVE-2022-31860 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published09/06/2022 | SeverityCritical |