OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.

Project Subscriptions

Vendors Products
Openremote Subscribe
Openremote Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.
Title OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference
First Time appeared Openremote
Openremote openremote
Weaknesses CWE-639
CPEs cpe:2.3:a:openremote:openremote:1.13.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.15.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.15.2:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.16.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.16.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.17.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.17.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.17.2:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.17.3:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.18.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.20.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.20.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.20.2:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.21.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.22.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.22.1:*:*:*:*:*:*:*
Vendors & Products Openremote
Openremote openremote
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-13T14:59:55.288Z

Reserved: 2026-08-13T11:16:27.835Z

Link: CVE-2026-73616

cve-icon Vulnrichment

Updated: 2026-08-13T14:58:16.916Z

cve-icon NVD

Status : Received

Published: 2026-08-13T12:17:26.480

Modified: 2026-08-13T15:20:20.240

Link: CVE-2026-73616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T12:45:03Z

Weaknesses