An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpenremote
APPOpenremote≤ 1.0.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
References
Related vulnerabilities
CVE-2026-39842CRITICAL9.9PL ✓same product
RCE przez injection wyrażeń w silniku reguł OpenRemote (IoT)
CVE-2026-62238HIGH7.2PL ✓same product
SQL injection w OpenRemote — eksport danych przez endpoint crosstab
CVE-2026-40882HIGH7.6same product
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import pat...
CVE-2026-41166HIGH7.0same product
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin...