Openremote operates an open-source IoT and building-automation platform where vulnerabilities cluster around injection and access-control weaknesses, including code injection, expression-language injection, XML external-entity handling, and improper authorization mechanisms. These classes reflect the platform's role as a server-side orchestration layer that processes user-supplied configuration and commands, and the observed patterns suggest opportunities for input-validation and privilege-boundary hardening. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openremote over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56784HIGH OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete | Jun 23, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-39842CRITICAL OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code exe | Apr 15, 2026 | 9.9 | 32 | NO | NO |
CVE-2026-62238HIGH OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset di | Jul 17, 2026 | 7.2 | 31 | NO | NO |
CVE-2022-31860CRITICAL An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule. | Sep 6, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-65009MEDIUM OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with | Jul 21, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-40882HIGH OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An au | Apr 22, 2026 | 7.6 | 25 | NO | NO |
CVE-2026-41166HIGH OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak re | Apr 22, 2026 | 7.0 | 23 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openremote.
Media articles that mention a CVE ID that affects a product developed by Openremote — matched by CVE ID, not by vendor name.