Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and message content from all realms. | |
| Title | OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API | |
| First Time appeared |
Openremote
Openremote openremote |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openremote
Openremote openremote |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T14:50:45.924Z
Reserved: 2026-08-27T11:11:30.933Z
Link: CVE-2026-81679
No data.
Status : Received
Published: 2026-08-27T17:20:57.150
Modified: 2026-08-27T17:20:57.150
Link: CVE-2026-81679
No data.
OpenCVE Enrichment
No data.