Executive brief
OpenRemote is an open-source platform for managing smart building and IoT devices. A security flaw in its KNX device import tool allows an authenticated user to upload a specially crafted file that forces the server to read sensitive local files, such as system passwords or configuration data. This could lead to the exposure of administrative credentials or internal network information, potentially allowing an attacker to gain deeper access to the system.
Technical details
An XML External Entity (XXE) vulnerability exists in OpenRemote's KNXProtocol.startAssetImport() method. While a previous fix (CVE-2026-40882) secured the Velbus handler, the KNX handler still uses unprotected Saxon XSLT and XMLInputFactory instances to process user-uploaded ETS project ZIP files. An authenticated attacker with low privileges can upload a malicious XML file within a ZIP archive to trigger external entity resolution. This allows for arbitrary file read from the server filesystem (e.g., /etc/passwd, configuration files) and potential Server-Side Request Forgery (SSRF). The issue is fixed in version 1.24.2.
Affected products
- OpenRemote openremote-agent <= 1.24.1
Timeline
- 2026-06-12: advisory: GitHub Advisory published
- 2026-07-06: disclosed: CVE-2026-54640 assigned
- 2026-06-12: patched: Version 1.24.2 released