CVE-2026-65009
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve operational logs from all tenants, exposing asset IDs, agent connection details, rule names, and protocol errors across the multi-tenant deployment.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| openremote | openremote | 0 < 1.26.2 | affected |
| openremote | openremote | 1.26.2 | unaffected |
Weaknesses
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
References
- https://github.com/openremote/openremote/security/advisories/GHSA-fv8q-rwj8-2c55
- https://www.vulncheck.com/advisories/openremote-before-information-disclosure-via-syslog-rest-api
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.