Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-57168

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
Back to all
CVE

CVE-2026-57168

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

Summary

OpenRemote Manager is vulnerable to a cross-tenant Insecure Direct

Object Reference (IDOR) in the bulk alarm deletion endpoint. An

authenticated user in any realm can delete alarms belonging to other

realms (tenants) by supplying arbitrary alarm IDs. The vulnerability

exists because the bulk removeAlarms() method only verifies that the

caller's own realm is active and accessible, but never checks whether

the targeted alarm IDs belong to the caller's realm before deleting

them.

This allows any user with alarm write permissions in their own realm

to permanently destroy alarm records — including safety-critical and

security alerts — belonging to any other tenant on the same OpenRemote

installation.

------------------------------------------

[Additional Information]

The singular removeAlarm() method correctly validates that the

target alarm's realm matches the caller's access:

    // CORRECT (singular):

    SentAlarm alarm = alarmService.getAlarm(alarmId);

    if (!isRealmActiveAndAccessible(alarm.getRealm())) {

        throw new ForbiddenException(...);

    }

The plural removeAlarms() method is missing this per-alarm realm

check and only validates the caller's own realm — a check that is

trivially satisfied for any authenticated user:

 // VULNERABLE (plural):
public void removeAlarms(RequestParams requestParams, List<Long> alarmIds) {
    if (!isRealmActiveAndAccessible(getAuthenticatedRealmName())) {  
        throw new ForbiddenException(...);  // always passes for any auth user
    }
    List<SentAlarm> alarms = alarmService.getAlarms(alarmIds);  // no realm filter
    alarmService.removeAlarms(alarms, alarmIds);                // no realm filter
}

The underlying service queries contain no realm scoping:

   ```

 // AlarmService.getAlarms(List<Long>):

    "select sa from SentAlarm sa where sa.id in :ids"

    // no realm filter

    // AlarmService.removeAlarms():

    "delete from SentAlarm sa where sa.id in :ids"

    // no realm filter

Alarm IDs are sequential auto-increment Long values (JPA
@GeneratedValue), making them trivially enumerable.
[Vulnerability Type]
Insecure Direct Object Reference (IDOR) / Missing Authorization
CWE-639: Authorization Bypass Through User-Controlled Key
CWE-862: Missing Authorization
------------------------------------------
[Vendor of Product]
OpenRemote Inc. (openremote.io)
------------------------------------------
[Affected Product Code Base]
OpenRemote Manager - current version as of 2026
(github.com/openremote/openremote)
------------------------------------------
[Affected Component]
org.openremote.manager.alarm.AlarmResourceImpl#removeAlarms()
org.openremote.manager.alarm.AlarmService#getAlarms(List<Long>)
org.openremote.manager.alarm.AlarmService#removeAlarms()
File: manager/src/main/java/org/openremote/manager/alarm/AlarmResourceImpl.java
File: manager/src/main/java/org/openremote/manager/alarm/AlarmService.java
------------------------------------------
[Attack Type]
Remote (authenticated)
------------------------------------------
[CVE Impact Other]
Cross-tenant permanent destruction of alarm records, including
safety-critical and security alerts in IoT environments. Also enables
cross-tenant alarm enumeration (presence disclosure of alarm IDs
across all tenants).
------------------------------------------
[Attack Vectors]
1. Attacker registers or obtains any low-privilege account in any realm
   on the target OpenRemote installation (or uses an existing account).
2. Attacker enumerates alarm IDs belonging to other realms by sending
   bulk delete requests with sequential IDs (presence confirmed by
   404 vs 200 response codes).
3. Attacker issues a single bulk delete request containing IDs of
   alarms belonging to victim realm(s).
4. Alarms are permanently deleted with no authorization error.
PoC:

Tenant A (attacker) : realm = "tenant-a"

                      user  = attacker@tenant-a.com

                      role  = WRITEALARMSROLE

Tenant B (victim)   : realm = "tenant-b"

                      alarms with IDs 1174,1173, 1180 exist

DELETE /api/smartcity/alarm HTTP/2

Content-Type: application/json

[1174,1173, 1180]  /// <- alarm ID 

```

<img width="1280" height="404" alt="image" src="https://github.com/user-attachments/assets/ffbebea2-2248-42a0-bb22-7a0dc51c78ce" />

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
8.6
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://github.com/openremote/openremote/security/advisories/GHSA-h3m5-97jq-qjrf, https://github.com/openremote/openremote/commit/9fad55e5a448c82772d241d395826e5d6fe1ce2d, https://github.com/openremote/openremote, https://github.com/openremote/openremote/blob/master/manager/src/main/java/org/openremote/manager/alarm/AlarmResourceImpl.java, https://github.com/openremote/openremote/blob/master/manager/src/main/java/org/openremote/manager/alarm/AlarmService.java

Severity

9.6

CVSS Score
0
10

Basic Information

Base CVSS
9.6
EPSS Probability
0.00258%
EPSS Percentile
0.17664%
Introduced Version
0
Fix Available
1.25.0

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading