Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39842

32
FAUCET Score

OpenRemote versions 1.21.0 and below contain critical expression injection vulnerabilities in both the JavaScript and Groovy rules engines that allow unauthenticated arbitrary code execution. The JavaScript rules engine lacks sandboxing and class filtering, while the Groovy engine's security filter is defined but not activated. Any user with write:rules role can exploit these flaws to execute malicious code with full JVM privileges, enabling remote code execution as root, credential theft, and cross-tenant data access. The vulnerability carries a CVSS score of 9.9 (Critical) with a network-based attack vector requiring only low privilege (write:rules role) and no user interaction, affecting system confidentiality, integrity, and availability across tenant boundaries. The attack complexity is low, making exploitation straightforward for any authenticated attacker with the specified role. The potential impact is severe, including complete server compromise, sensitive data exfiltration, and bypassing multi-tenant isolation controls. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows no public exploit code availability. Community attention appears limited given the low EPSS score of 0.0006. Organizations running OpenRemote should prioritize upgrading to version 1.22.0 to remediate these critical flaws, particularly if instances are accessible to untrusted users with administrative roles.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.22.0CPE matchmatch criteria
cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.92%
Probability of exploitation in next 30 days
EPSS Percentile
56.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0092 is in the 65th percentile among its peer group of 1,128 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: io.openremote:openremote-managerFixed in: 1.22.0

Vendor Advisories (1)

mavenGHSA-7mqr-33rv-p3mpcritical

Expression Injection in OpenRemote

Apr 14, 2026

References

github.com / openremote/openremote/releases/tag/1.22.0
ProductRelease Notes
github.com / openremote/openremote/security/advisories/GHSA-7mqr-33rv-p3mp
ExploitVendor Advisory