CVE-2026-41166 Details
Description
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segment when talking to the identity provider but does not check that the caller may administer that realm. This could result in a privilege escalation to `master` realm administrator if the attacker controls any user in `master` realm. Version 1.22.1 fixes the issue.
A privilege escalation vulnerability has been identified in OpenRemote versions prior to 1.22.1. The issue arises in the Manager API, where a user with the 'write:admin' role in one Keycloak realm can update realm roles for users in another realm, including the 'master' realm. This vulnerability exists because the API does not properly verify if the caller has the authority to administer the targeted realm. As a result, an attacker could potentially escalate privileges to become a 'master' realm administrator, especially if they have control over a user in the 'master' realm.
Users are advised to update OpenRemote to version 1.22.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openremote/openremote/security/advisories/GHSA-49vv-25qx-mg44 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/openremote/openremote/releases/tag/1.22.1 | [email protected] | ProductRelease Notes |
| https://github.com/openremote/openremote/security/advisories/GHSA-49vv-25qx-mg44 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openremote openremote | < 1.22.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | Initial Analysis | [email protected] |
| Apr 23, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | New CVE Received | [email protected] |