Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 01 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of realms from the request, rather than all realms. Because HashSet iteration order is non-deterministic, an authenticated attacker who includes alarm-asset links from both their own realm and a victim realm can, with roughly 50% probability per request (retryable), persist cross-tenant links and disclose victim asset names (returned via @Formula fields) through GET requests on the attacker's own alarm. Fixed in 1.27.0. | |
| Title | openremote before 1.27.0 Cross-Tenant IDOR via setAssetLinks | |
| First Time appeared |
Openremote
Openremote openremote |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openremote
Openremote openremote |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-03T15:37:56.688Z
Reserved: 2026-07-29T13:06:35.178Z
Link: CVE-2026-67310
Updated: 2026-08-03T14:46:50.809Z
Status : Received
Published: 2026-08-01T13:17:00.850
Modified: 2026-08-03T17:16:40.947
Link: CVE-2026-67310
No data.
OpenCVE Enrichment
Updated: 2026-08-02T03:15:03Z