CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2026-66013

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-25
Last Modified2026-07-25
Data SourcesNVD

Vulnerability Description

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相關漏洞威脅