Description
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.
Published: 2026-08-13
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.
Title OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference
First Time appeared Openremote
Openremote openremote
Weaknesses CWE-639
CPEs cpe:2.3:a:openremote:openremote:1.13.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.15.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.15.2:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.16.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.16.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.17.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.17.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.17.2:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.17.3:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.18.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.20.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.20.1:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.20.2:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.21.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.22.0:*:*:*:*:*:*:*
cpe:2.3:a:openremote:openremote:1.22.1:*:*:*:*:*:*:*
Vendors & Products Openremote
Openremote openremote
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openremote Openremote
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-13T14:59:55.288Z

Reserved: 2026-08-13T11:16:27.835Z

Link: CVE-2026-73616

cve-icon Vulnrichment

Updated: 2026-08-13T14:58:16.916Z

cve-icon NVD

Status : Received

Published: 2026-08-13T12:17:26.480

Modified: 2026-08-13T15:20:20.240

Link: CVE-2026-73616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T12:45:03Z

Weaknesses