HIGH🇵🇱 Wersja polska

CVE-2026-62238

CVSS 7.2v4.0pub. 2026-07-17upd. 2026-07-30

OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openremote

    APP
    Openremote
    < 1.26.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-39842CRITICAL9.9PL ✓same product

RCE przez injection wyrażeń w silniku reguł OpenRemote (IoT)

CVE-2022-31860CRITICAL9.8PL ✓same product

RCE w OpenRemote — wykonanie kodu przez spreparowaną regułę Groovy

CVE-2026-40882HIGH7.6same product

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import pat...

CVE-2026-41166HIGH7.0same product

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin...