THREAT OPS › Threat News › [NVD] CVE-2026-67310 (MEDIUM 5.4) — OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of re
[NVD] CVE-2026-67310 (MEDIUM 5.4) — OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of re
CVE-2026-67310 CVSS: 5.4 MEDIUM Published: 2026-08-01T13:17:00.850
OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of realms from the request, rather than all realms. Becau
Indicators of compromise
- CVE-2026-67310cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67310