CyberRota Analysis
AI-GeneratedOpenRemote versions prior to 1.26.2 are vulnerable to an information disclosure flaw in the SyslogResource REST endpoint, allowing attackers with the read:rules role to access operational logs across all tenants. This exposure can reveal sensitive information such as asset IDs, agent connection details, and protocol errors, posing a risk to multi-tenant environments. Organizations utilizing OpenRemote should prioritize updating to version 1.26.2 or later to mitigate this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve operational logs from all tenants, exposing asset IDs, agent connection details, rule names, and protocol errors across the multi-tenant deployment.