Critical severityNVD Advisory· Published Jul 25, 2026· Updated Jul 30, 2026
CVE-2026-66013
CVE-2026-66013
Description
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.26.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.