CVE-2026-65009: OpenRemote before 1.26.2 Information Disclosure via Syslog REST API
OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve operational logs from all tenants, exposing asset IDs, agent connection details, rule names, and protocol errors across the multi-tenant deployment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenRemoteto a version that resolves this vulnerability.Fixed in 1.26.2 - Compensating control
Restrict access to the Syslog REST endpoint (GET /api/{realm}/syslog/event) so that users with the read:rules role cannot query operational logs across other tenants/realms.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65009?
The severity of CVE-2026-65009 is medium with a CVSS score of 4.3.
How do I fix CVE-2026-65009?
To fix CVE-2026-65009, upgrade OpenRemote to version 1.26.2 or later.
What type of vulnerability is CVE-2026-65009?
CVE-2026-65009 is classified as an information disclosure vulnerability.
What is affected by CVE-2026-65009?
CVE-2026-65009 affects OpenRemote versions prior to 1.26.2.
Who is impacted by CVE-2026-65009?
Attackers with the read:rules role could exploit CVE-2026-65009 to access sensitive operational logs.