CVE-2026-73616: OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73616?
The severity of CVE-2026-73616 is rated as medium with a score of 6.5.
How do I fix CVE-2026-73616?
To fix CVE-2026-73616, ensure that access controls are properly enforced to prevent realm administrators from deleting notifications in other realms.
What types of attacks are possible due to CVE-2026-73616?
CVE-2026-73616 allows attackers with write:admin role to delete notifications belonging to other realms, leading to potential disruption of services.
Who is affected by CVE-2026-73616?
CVE-2026-73616 affects users of OpenRemote, particularly those with the write:admin role in any realm.
When was CVE-2026-73616 published?
CVE-2026-73616 was published on August 13, 2026.