CVE-2026-73616
Last modified
CVE-2026-73616 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks..
Description
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| openremote | openremote | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-73616?
How severe is CVE-2026-73616?
How do I fix CVE-2026-73616?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73610SiYuan before v3.7.4 contains an information disclosure vuln…6.9
- CVE-2026-73611File Browser versions from 2.50.0 through 2.63.21 fail to va…7.6
- CVE-2026-73612File Browser before v2.63.22 fails to validate access rules …8.6
- CVE-2026-73613filebrowser versions before 2.63.19 contain an out-of-scope …8.2
- CVE-2026-73614Network-AI ClaudeHookBridge before 5.15.1 truncates the targ…8.8
- CVE-2026-73615Network-AI versions before 5.15.1 contain a security matcher…8.8
- CVE-2026-73617Budibase before 3.40.0 contains a NoSQL injection vulnerabil…7.1
- CVE-2026-73618Budibase Server before 3.40.0 contains a NoSQL injection vul…8.7
- CVE-2026-73619GitPython before 3.1.57 contains an incomplete denylist in t…7.1
- CVE-2026-7362IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6…6.5
- CVE-2026-73620GitPython before 3.1.57 fails to guard git option forwarding…8.1
- CVE-2026-73621GitPython before 3.1.56 contains an argument injection vulne…5.4
Are you affected by CVE-2026-73616?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
