CVE-2026-56120: OpenRemote < 1.25.0 IDOR via Bulk Alarm Deletion Endpoint
Published Jun 23, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-56784.
Affected Software
1 affected component
OpenRemote OpenRemote<1.25.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenRemoteto a version that resolves this vulnerability.Fixed in 1.25.0
Event History
Jun 23, 2026
CVE Published
via MITRE·08:54 PM
Rejected
via MITRE·08:54 PM
Rejected
via MITRE·09:03 PM
Data Sourced
via NVD·09:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-56120?
CVE-2026-56120 has a severity score of 8.1, classified as high.
2
How do I fix CVE-2026-56120?
To fix CVE-2026-56120, upgrade OpenRemote to version 1.25.0 or later.
3
What type of vulnerability is CVE-2026-56120?
CVE-2026-56120 is an insecure direct object reference (IDOR) vulnerability.
4
Who is affected by CVE-2026-56120?
Authenticated users in OpenRemote versions prior to 1.25.0 are affected by CVE-2026-56120.
5
What can happen if CVE-2026-56120 is exploited?
If CVE-2026-56120 is exploited, an attacker can permanently delete alarms belonging to other tenants.