OpenRemote versions 1.21.0 and below contain critical expression injection vulnerabilities in both the JavaScript and Groovy rules engines that allow unauthenticated arbitrary code execution. The JavaScript rules engine lacks sandboxing and class filtering, while the Groovy engine's security filter is defined but not activated. Any user with write:rules role can exploit these flaws to execute malicious code with full JVM privileges, enabling remote code execution as root, credential theft, and cross-tenant data access. The vulnerability carries a CVSS score of 9.9 (Critical) with a network-based attack vector requiring only low privilege (write:rules role) and no user interaction, affecting system confidentiality, integrity, and availability across tenant boundaries. The attack complexity is low, making exploitation straightforward for any authenticated attacker with the specified role. The potential impact is severe, including complete server compromise, sensitive data exfiltration, and bypassing multi-tenant isolation controls. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows no public exploit code availability. Community attention appears limited given the low EPSS score of 0.0006. Organizations running OpenRemote should prioritize upgrading to version 1.22.0 to remediate these critical flaws, particularly if instances are accessible to untrusted users with administrative roles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.22.0CPE matchmatch criteria | cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.