CVE-2026-73616 PUBLISHED

OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference

Assigner: VulnCheck
Reserved: 13.08.2026 Published: 13.08.2026 Updated: 13.08.2026

OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor openremote
Product openremote
Versions Default: affected

Credits

  • arpitjain099 reporter

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE