Unrated severityNVD Advisory· Published Jul 25, 2026· Updated Jul 29, 2026
OpenRemote before 1.26.2 Authentication Bypass via Console Registration
CVE-2026-66013
Description
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
Affected products
1- Range: <1.26.2
Patches
Vulnerability mechanics
References
2- github.com/openremote/openremote/security/advisories/GHSA-gpfc-h59v-63cvmitrevendor-advisory
- www.vulncheck.com/advisories/openremote-before-authentication-bypass-via-console-registrationmitrethird-party-advisory
News mentions
0No linked articles in our index yet.