Junglewise Threat Intelligence

CVE-2026-73616: OpenRemote notification deletion cross-realm authorization bypass

CVE-2026-73616 · Severity: medium · CVSS 6.5 · Published 2026-08-13

Technologies: OpenRemote. Vendors: OpenRemote.

Executive brief

OpenRemote is an open-source IoT platform that manages notifications across multiple customer tenants (realms). A flaw in the notification deletion API allows any tenant administrator to delete notifications belonging to other customers' environments, including the master realm. This enables data destruction and operational disruption across organization boundaries without proper authorization.

Technical details

The vulnerability is a cross-realm Insecure Direct Object Reference (IDOR) / authorization bypass in the notification deletion endpoints of NotificationResourceImpl.java. The delete methods (removeNotifications and removeNotification) only check for the write:admin role without validating that the caller's realm matches the target notification's realm, unlike the hardened read path which calls resolveAndAuthoriseRealm(). An authenticated user with write:admin role in one realm can send DELETE requests with arbitrary notification IDs or realm parameters to removeNotifications(), bypassing realm boundary checks. The root cause mirrors CVE-2026-57168 (removeAlarms IDOR), where role-based access control was enforced but per-object realm validation was omitted. The underlying NotificationService.removeNotification(Long id) executes a bare delete with no realm filter. Patch is available in version 1.28.0.

Affected products

  • OpenRemote OpenRemote <= 1.27.1

Timeline

  • 2026-07-29: disclosed
  • 2026-08-13: advisory
  • 2026: patched: Patched in version 1.28.0

References

Related threats