Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks. | |
| Title | OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference | |
| First Time appeared |
Openremote
Openremote openremote |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:openremote:openremote:1.13.1:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.14.0:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.15.0:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.15.1:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.15.2:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.16.0:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.16.1:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.17.0:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.17.1:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.17.2:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.17.3:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.18.0:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.19.0:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.20.0:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.20.1:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.20.2:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.21.0:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.22.0:*:*:*:*:*:*:* cpe:2.3:a:openremote:openremote:1.22.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Openremote
Openremote openremote |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:59:55.288Z
Reserved: 2026-08-13T11:16:27.835Z
Link: CVE-2026-73616
Updated: 2026-08-13T14:58:16.916Z
Status : Received
Published: 2026-08-13T12:17:26.480
Modified: 2026-08-13T15:20:20.240
Link: CVE-2026-73616
No data.
OpenCVE Enrichment
Updated: 2026-08-13T12:45:03Z
-
CWE-639
Authorization Bypass Through User-Controlled Key