THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67310 (MEDIUM 5.4) — OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of re

[NVD] CVE-2026-67310 (MEDIUM 5.4) — OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of re

mednvdPublished 2026-08-01

CVE-2026-67310 CVSS: 5.4 MEDIUM Published: 2026-08-01T13:17:00.850

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of realms from the request, rather than all realms. Becau

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67310