← Terug naar overzicht

OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API. The flaw allows per-realm tenant administrators with read:admin credentials to access sent notifications from all tenants, not just their own realm. Exploitation requires only a zero-parameter GET request to the notification endpoint, making it trivially easy to abuse. Sensitive notification metadata and message content from all realms can be retrieved by an attacker with access to any single realm. The vulnerability has been addressed in OpenRemote version 1.28.0. This represents a significant access control failure in a multi-tenant architecture. The issue is documented in both the NVD and GitHub Security Advisories. Organizations running OpenRemote in multi-tenant deployments are particularly at risk. The vulnerability could expose confidential communications between administrators and users across all tenants.

Affected products

  • OpenRemote before 1.28.0

Related CVE's

  • CVE-2026-81679

Categories

  • Data Breach & Exfiltration
  • Enterprise Applications
  • Identity & Access
  • Web Technologies