7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether io.openremote:openremote-manager is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.6
CVE-2026-56784
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
UNKNOWN
GHSA-cgfv-jrfp-2r7v
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
HIGH 7.7
CVE-2026-54641
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
MEDIUM 4.3
CVE-2026-49439
OpenRemote read-only asset users can write predicted datapoints
HIGH 7.6
CVE-2026-40882
OpenRemote has XXE in Velbus Asset Import
CRITICAL 9.9
CVE-2026-39842
Expression Injection in OpenRemote
HIGH 7.0
CVE-2026-41166
OpenRemote has Improper Access Control via updateUserRealmRoles function
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes