CVE-2026-49439
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Summary
OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only read:assets privileges to write predicted datapoints. Version 1.24.1 fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| openremote | openremote | < 1.24.1 | affected |
Weaknesses
- CWE-862: CWE-862: Missing Authorization
References
- https://github.com/openremote/openremote/security/advisories/GHSA-xj53-j257-hxvg
- https://github.com/openremote/openremote/commit/583dbbfb96076ba099be8729ddf506acf9e48325
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.