io.openremote:openremote-manager
Maven8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting io.openremote:openremote-managerpage 1 of 1
- CVE-2026-39842CRITICALCVSS 9.9EG 9.9✓ Fixed in 1.22.02026-04-15
vulnerable: 1.10.0 ... 1.9.0 (47 versions)
OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes …
- CVE-2026-40882HIGHCVSS 7.6EG 7.6✓ Fixed in 1.22.02026-04-22
vulnerable: 1.10.0 ... 1.9.0 (47 versions)
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigg…
- CVE-2026-41166HIGHCVSS 7.0EG 7.0✓ Fixed in 1.22.12026-04-22
vulnerable: 1.10.0 ... 1.9.0 (48 versions)
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. T…
- CVE-2026-49439MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.24.12026-07-06
vulnerable: 1.10.0 ... 1.9.0 (52 versions)
OpenRemote read-only asset users can write predicted datapoints # Summary The predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. The endpoint: ```text PUT /api/{realm}/asse…
- CVE-2026-54641HIGHCVSS 7.7EG 7.7✓ Fixed in 1.24.22026-07-06
vulnerable: 1.10.0 ... 1.9.0 (53 versions)
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl ### Summary A realm admin of tenant B can read the profile, client roles, and realm roles of any user in any other realm (including the master realm) by supplying…
- CVE-2026-56784HIGHCVSS 8.1EG 8.3✓ Fixed in 1.25.02026-06-23
vulnerable: 1.10.0 ... 1.9.0 (54 versions)
OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary a…
- CVE-2026-57168CRITICALCVSS 9.6EG 9.6✓ Fixed in 1.25.02026-06-19
vulnerable: 1.10.0 ... 1.9.0 (54 versions)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete) ### Summary OpenRemote Manager is vulnerable to a cross-tenant Insecure Direct Object Reference (IDOR) in the bulk alarm deletion endpoint. An authenticated user in any realm…
- CVE-2026-62238HIGHCVSS 7.2EG 7.2✓ Fixed in 1.26.02026-07-17
vulnerable: 1.10.0 ... 1.9.0 (55 versions)
OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with as…
Check whether io.openremote:openremote-manager is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for io.openremote:openremote-manager CVEs against the assets you own.
Start Free Scan →