CVE-2026-81679
Severity CVSS v4.0:
HIGH
Type:
CWE-200
Information Leak / Disclosure
Publication date:
27/08/2026
Last modified:
27/08/2026
Description
OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and message content from all realms.
Impact
Base Score 4.0
8.30
Severity 4.0
HIGH
Base Score 3.x
7.70
Severity 3.x
HIGH



