CyberSec.Space Logo
返回 CVE 浏览器

CVE-2026-66013

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-25
Last Modified2026-07-25
Data SourcesNVD

Vulnerability Description

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相关漏洞威胁