OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and message content from all realms.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and message content from all realms. | |
| Title | OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API | |
| First Time appeared |
Openremote
Openremote openremote |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openremote
Openremote openremote |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T14:50:45.924Z
Reserved: 2026-08-27T11:11:30.933Z
Link: CVE-2026-81679
No data.
Status : Received
Published: 2026-08-27T17:20:57.150
Modified: 2026-08-27T17:20:57.150
Link: CVE-2026-81679
No data.
OpenCVE Enrichment
No data.