Vulnerability record · CVE-2026-41166 · published 22 April 2026
CVE-2026-41166: Openremote improper access control vulnerability
Openremote · Openremote
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segment when talking to the identity provider but does not check that the caller may administer that realm. This could result in a privilege escalation to `master` realm administrator if the attacker controls any user in `master` realm. Version 1.22.1 fixes the issue.
Description
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segment when talking to the identity provider but does not check that the caller may administer that realm. This could result in a privilege escalation to `master` realm administrator if the attacker controls any user in `master` realm. Version 1.22.1 fixes the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/openremote/openremote/releases/tag/1.22.1 | ProductRelease Notes |
| https://github.com/openremote/openremote/security/advisories/GHSA-49vv-25qx-mg44 | ExploitVendor Advisory |
| https://github.com/openremote/openremote/security/advisories/GHSA-49vv-25qx-mg44 | ExploitVendor Advisory |
Track CVE-2026-41166 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-41166), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.