Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81679— OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API

Quick assessment

Affected
openremote openremote
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenRemote 在 1.28.0 之前的版本中,其通知 REST API 存在一个跨 Realm(领域/租户)的信息泄露漏洞。该漏洞允许特定 Realm 的租户管理员读取所有租户已发送的通知,包括通知消息正文。拥有单个 Realm 中 权限的攻击者,可以通过向通知端点发送一个无参数的 GET 请求,从而获取来自所有 Realm 的敏感通知元数据和消息内容。

CVSS 7.7 · High

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 2

VendorProduct Version RangeStatus
openremote openremote < 1.28.0 affected
1.28.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81679

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API
Source: CVE Program / CVE List V5
Vulnerability Description
OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and message content from all realms.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
openremote openremote 0 ~ 1.28.0 -

II. Public POCs for CVE-2026-81679

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81679

登录查看更多情报信息。

Vendor Advisories for CVE-2026-81679 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-81679

No comments yet


Leave a comment