Beveiligingsadvies

CVE-2026-81679

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-27 14:50:45
Laatst bijgewerkt 2026-08-28 15:59:40
Toegewezen door VulnCheck
CVSS-score 8.3
Status PUBLISHED

Beschrijving

OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and message content from all realms.