Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2026-41166— OpenRemote has Improper Access Control via updateUserRealmRoles function

CVSS 7.0 · High EPSS 0.05% · P15
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-41166

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenRemote has Improper Access Control via updateUserRealmRoles function
Source: NVD (National Vulnerability Database)
Vulnerability Description
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segment when talking to the identity provider but does not check that the caller may administer that realm. This could result in a privilege escalation to `master` realm administrator if the attacker controls any user in `master` realm. Version 1.22.1 fixes the issue.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
访问控制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenRemote 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenRemote是OpenRemote开源的一个开源物联网平台。 OpenRemote 1.22.1之前版本存在访问控制错误漏洞,该漏洞源于具有write:admin权限的用户可以调用Manager API更新其他领域(包括master)的用户Keycloak领域角色,可能导致权限提升。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
openremoteopenremote < 1.22.1 -

II. Public POCs for CVE-2026-41166

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-41166

登录查看更多情报信息。
Advisory · 1

IV. Related Vulnerabilities

V. Comments for CVE-2026-41166

No comments yet


Leave a comment