CVE-2026-49439
OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- CWE
- CWE-862
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- openremote openremote
Weakness type
Related vulnerabilities
- CVE-2026-90454 — A deployment mode intended to expose only read access to a bundled packet-analysis component's...
- CVE-2026-90448 — A deployment mode intended to expose only read access to stored data proxies a set of application...
- CVE-2026-50025 — Mousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie state
- CVE-2026-68535 — Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Area REST API block-create path letting an editor reference files outside their file-manager permissions
- CVE-2026-81916 — Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object
- CVE-2026-81915 — In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
- CVE-2026-62089 — WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control vulnerability
- CVE-2026-62137 — WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability