Junglewise Threat Intelligence

CVE-2026-81679: OpenRemote cross-realm information disclosure in Notification REST API

CVE-2026-81679 · Severity: high · CVSS 7.7 · Published 2026-08-27

Technologies: OpenRemote. Vendors: OpenRemote.

Executive brief

OpenRemote is an open-source IoT platform that manages remote devices and notifications across multiple customer organizations (realms). A flaw in the Notification REST API allows a tenant administrator from one organization to view sensitive notification data—including message content and metadata—from every other organization on the same system. An attacker can exploit this with standard read permissions to extract confidential information without additional privileges or user interaction.

Technical details

This is an access control vulnerability (CWE-200, CWE-284) in the NotificationResourceImpl and NotificationService classes. The root cause is that the realm-scoping guard (min-criteria check) is conditional on the isRemove flag and is skipped for read operations, allowing an unauthenticated query to return SentNotification records from all realms. The SentNotification entity lacks a realm column, and no realm predicate is injected by processCriteria during reads. An attacker with read:admin credentials in one realm can issue a zero-parameter GET request to /api/{callerRealm}/notification and retrieve all tenants' notification metadata and message bodies. The attack requires only network access and a valid per-realm admin token; no super-user or cross-realm privileges are required. Patch: upgrade to version 1.28.0 or later, which enforces realm-based access control on the read path independently of the delete flag.

Affected products

  • OpenRemote OpenRemote before 1.28.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Version 1.28.0 contains fix
  • 2026-08-13: advisory: GitHub Security Advisory GHSA-6ff4-4frc-r287

References

Related threats