CVE-2026-56784 PUBLISHED

OpenRemote Manager - Cross-Tenant IDOR in Bulk Alarm Deletion

Assigner: VulnCheck
Reserved: 23.06.2026 Published: 23.06.2026 Updated: 23.06.2026

OpenRemote Manager before 1.24.2 contains an insecure direct object reference vulnerability in the removeAlarms() method that allows authenticated users to delete alarms from other tenants by supplying arbitrary alarm IDs. The bulk deletion endpoint fails to validate that targeted alarm IDs belong to the caller's realm, enabling cross-tenant permanent destruction of safety-critical and security alerts.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.2

Product Status

Vendor openremote
Product openremote
Versions Default: unaffected
  • affected from 0 to 1.24.2 (excl.)
  • Version 1.24.2 is unaffected

Credits

  • Forklit reporter
  • vladkoniakhinmob reporter

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE