CyberRota Analysis
AI-GeneratedOpenRemote versions prior to 1.28.0 are vulnerable to a cross-realm information disclosure flaw in the Notification REST API, enabling tenant administrators to access sensitive notifications from all tenants. This vulnerability allows attackers with read:admin credentials to exploit the API and retrieve confidential message content across different realms. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and message content from all realms.