Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.openremote/openremote-manager
  4. ›
  5. CVE-2026-54641

CVE-2026-54641: OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

July 6, 2026

A realm admin of tenant B can read the profile, client roles, and realm roles of any user in any other realm (including the master realm) by supplying the target user’s UUID in the REST API path. Three read endpoints in UserResourceImpl check whether the caller holds the read:admin role but omit a check that the target user belongs to the caller’s own realm. The vulnerability enables cross-tenant user enumeration and privilege-level reconnaissance. On a multi-tenant deployment the master realm administrator account is reachable from any tenant realm admin.

References

  • github.com/advisories/GHSA-xqr9-4wvv-gvch
  • github.com/openremote/openremote/commit/de89b8d3af272d717bf297934c2cbc97243f08b7
  • github.com/openremote/openremote/security/advisories/GHSA-xqr9-4wvv-gvch
  • nvd.nist.gov/vuln/detail/CVE-2026-54641

Code Behaviors & Features

Detect and mitigate CVE-2026-54641 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.24.2

Fixed versions

  • 1.24.2

Solution

Upgrade to version 1.24.2 or above.

Impact 7.7 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-639: Authorization Bypass Through User-Controlled Key

Source file

maven/io.openremote/openremote-manager/CVE-2026-54641.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 18 Jul 2026 00:23:11 +0000.