VYPR

Maven package

io.openremote/openremote-manager

pkg:maven/io.openremote/openremote-manager

Vulnerabilities (3)

  • CVE-2026-41166HigApr 22, 2026
    affected < 1.22.1fixed 1.22.1

    OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segmen

  • CVE-2026-40882HigApr 22, 2026
    affected < 1.22.0fixed 1.22.0

    OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML external entity processing, which

  • CVE-2026-39842CriApr 15, 2026
    affected < 1.22.0fixed 1.22.0

    OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-supplied scripts via Nashorn's Scrip