7 Total advisories
7 Vulnerabilities
0 Malware
Vulnerabilities
CRITICAL 9.6
CVE-2026-56784
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
UNKNOWN
GHSA-cgfv-jrfp-2r7v
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
HIGH 7.7
CVE-2026-54641
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
MEDIUM 4.3
CVE-2026-49439
OpenRemote read-only asset users can write predicted datapoints
HIGH 7.6
CVE-2026-40882
OpenRemote has XXE in Velbus Asset Import
CRITICAL 9.9
CVE-2026-39842
Expression Injection in OpenRemote
HIGH 7.0
CVE-2026-41166
OpenRemote has Improper Access Control via updateUserRealmRoles function
Ready to move
Start Securing
Free, no credit card | First findings in minutes