Executive brief
OpenRemote, an open-source IoT platform, contains a vulnerability that allows an administrator of one organization (tenant) to view sensitive information about users in other organizations, including the master system administrator. By exploiting this flaw, a malicious tenant admin can access user profiles, email addresses, and security roles across the entire platform. This breaks the isolation between different customers on a shared server and could be used to plan further attacks against high-level system accounts.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the UserResourceImpl.java component of OpenRemote Manager. Three REST API read endpoints (get, getUserClientRoles, and getUserRealmRoles) fail to validate that the requested user UUID belongs to the same realm as the authenticated caller. While these methods check for the 'read:admin' role, they lack the 'throwIfCannotAdminRealm' guard present in write-side methods. An attacker with realm-administrator privileges in any tenant can provide a target user's UUID to bypass realm boundaries and retrieve profiles and Keycloak roles from other realms, including the master realm. This issue is tracked as CVE-2026-54641 and is fixed in version 1.24.2.
Affected products
- OpenRemote openremote-manager < 1.24.2
Timeline
- 2026-06-12: patched: Fix committed to repository
- 2026-07-06: advisory: GHSA-xqr9-4wvv-gvch published