Loading market data...
← Back to CVE feed

CVE-2026-73616

MEDIUM CVSS 6.5 View on NVD ↗

Description

OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Published: Aug 13, 2026 12:17 UTC Modified: Aug 13, 2026 15:20 UTC