SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-65009

MEDIUM · CVSS 4.3 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

OpenRemote versions prior to 1.26.2 are vulnerable to an information disclosure flaw in the SyslogResource REST endpoint, allowing attackers with the read:rules role to access operational logs across all tenants. This exposure can reveal sensitive information such as asset IDs, agent connection details, and protocol errors, posing a risk to multi-tenant environments. Organizations utilizing OpenRemote should prioritize updating to version 1.26.2 or later to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65009
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve operational logs from all tenants, exposing asset IDs, agent connection details, rule names, and protocol errors across the multi-tenant deployment.