Back to overview

CVE-2026-65009

MEDIUM
4.3
CVSS 3.1
Description
OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve operational logs from all tenants, exposing asset IDs, agent connection details, rule names, and protocol errors across the multi-tenant deployment.

Metadata

CVE ID
CVE-2026-65009
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-21 11:32 UTC
Published
2026-07-21 11:39 UTC
Last updated
2026-07-21 11:39 UTC
Primary CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Vendor / Product
openremote / openremote
Sources
cve.org  ·  NVD

Severity & Metrics

4.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
openremote openremote 0 < 1.26.2, 1.26.2
Weakness (CWE)
CWESourceDescription
CWE-200 cna Exposure of Sensitive Information to an Unauthorized Actor
CVSS scores (2)
ScoreSeverityVersionSourceVector
5.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
4.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References (2)
Back to overview