Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41166

23
FAUCET Score

OpenRemote versions prior to 1.22.1 contain a cross-realm privilege escalation vulnerability in the Manager API. An attacker with write:admin permissions in one Keycloak realm can manipulate API calls to modify user roles across other realms, including the critical master realm, without proper authorization checks. This could enable an attacker to escalate privileges to master realm administrator level if they control any user account in the master realm. The vulnerability has a CVSS score of 7.0 (HIGH) with a network-based attack vector, high attack complexity, and no privilege or user interaction required. While the confidentiality impact is low, the integrity impact is high, allowing attackers to modify critical administrative roles and realm configurations. The EPSS score of 0.00036 indicates a low probability of exploitation in the wild, and there are currently no known public exploits or evidence of active exploitation. The vulnerability has not been added to the Known Exploited Vulnerabilities (KEV) catalog, and community attention remains minimal. OpenRemote released patch version 1.22.1 to address the issue by implementing proper authorization validation before allowing cross-realm role modifications. Organizations running vulnerable versions should prioritize upgrading to 1.22.1 or later, particularly if their OpenRemote instances manage critical IoT infrastructure.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.22.1CPE matchmatch criteria
cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
20.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 3rd percentile among its peer group of 8,918 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

mavenpatch availablevia ghsa
Product: io.openremote:openremote-managerFixed in: 1.22.1
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

mavenGHSA-49vv-25qx-mg44high

OpenRemote has Improper Access Control via updateUserRealmRoles function

Apr 22, 2026

References

github.com / openremote/openremote/releases/tag/1.22.1
ProductRelease Notes
github.com / openremote/openremote/security/advisories/GHSA-49vv-25qx-mg44
ExploitVendor Advisory