CVE-2026-65009
Received Received - Intake

Information Disclosure in OpenRemote via SyslogResource Endpoint

Vulnerability report for CVE-2026-65009, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: VulnCheck

Description

OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve operational logs from all tenants, exposing asset IDs, agent connection details, rule names, and protocol errors across the multi-tenant deployment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openremote openremote to 1.26.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-65009 is an information disclosure vulnerability in OpenRemote versions before 1.26.2. It affects the SyslogResource REST endpoint, which fails to filter operational logs by realm. Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve logs from all tenants, exposing sensitive data like asset IDs, agent connections, rule names, and protocol errors.

Detection Guidance

Check if unauthorized users with the read:rules role can access the GET /api/{realm}/syslog/event endpoint. Monitor logs for unusual access patterns or requests to this endpoint from non-admin users. Verify if operational logs from other tenants are being exposed.

Impact Analysis

If exploited, this vulnerability allows unauthorized access to operational logs across all tenants in a multi-tenant deployment. Attackers could gather sensitive information such as asset details, connection specifics, and errors, enabling further reconnaissance or targeted attacks against other tenants.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by exposing sensitive personal or health-related data. Unauthorized access to operational logs may violate data protection requirements, leading to legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade OpenRemote to version 1.26.2 or later. Restrict the read:rules role to only access logs within the user's realm. Alternatively, restrict the SyslogResource REST endpoint to the READ_LOGS_ROLE.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65009. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart