OpenRemote versions prior to 1.22.1 contain a cross-realm privilege escalation vulnerability in the Manager API. An attacker with write:admin permissions in one Keycloak realm can manipulate API calls to modify user roles across other realms, including the critical master realm, without proper authorization checks. This could enable an attacker to escalate privileges to master realm administrator level if they control any user account in the master realm. The vulnerability has a CVSS score of 7.0 (HIGH) with a network-based attack vector, high attack complexity, and no privilege or user interaction required. While the confidentiality impact is low, the integrity impact is high, allowing attackers to modify critical administrative roles and realm configurations. The EPSS score of 0.00036 indicates a low probability of exploitation in the wild, and there are currently no known public exploits or evidence of active exploitation. The vulnerability has not been added to the Known Exploited Vulnerabilities (KEV) catalog, and community attention remains minimal. OpenRemote released patch version 1.22.1 to address the issue by implementing proper authorization validation before allowing cross-realm role modifications. Organizations running vulnerable versions should prioritize upgrading to 1.22.1 or later, particularly if their OpenRemote instances manage critical IoT infrastructure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.22.1CPE matchmatch criteria | cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.