Security Advisory

CVE-2026-73616

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-13 11:28:18
Last updated 2026-08-13 14:59:55
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.