CVE-2026-66013: OpenRemote before 1.26.2 Authentication Bypass via Console Registration
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenRemoteto a version that resolves this vulnerability.Fixed in 1.26.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66013?
CVE-2026-66013 has a risk score of 64, indicating a medium severity vulnerability.
How do I fix CVE-2026-66013?
To fix CVE-2026-66013, upgrade OpenRemote to version 1.26.2 or later.
What kind of vulnerability is CVE-2026-66013?
CVE-2026-66013 is an authentication bypass vulnerability that allows unauthenticated access to console assets.
Who is affected by CVE-2026-66013?
Users of OpenRemote versions prior to 1.26.2 are affected by CVE-2026-66013.
What can attackers do with CVE-2026-66013?
Attackers can update existing console assets and overwrite metadata without authentication due to CVE-2026-66013.