CVE-2026-66013EPSS p50.7%
CVE-2026-66013CVE-2026-66013
Description
OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.
Scoring
| EPSS | 0.68% probability of exploitation · percentile 50.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-30 |