CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-62238: openremote before 1.26.0 (exclusive), 0 to before 1.26.0

CVE-2026-62238. CVSS 3.1 base score 8.8 (HIGH, NVD). EPSS 0.00498 (percentile 0.40616), scored 2026-10-06.

Affected technology

openremote · before 1.26.0 (exclusive)
openremote

openremote · 0 to before 1.26.0
openremote

Description’s affected range: before 1.26.0

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration. Vendor/CNA’s CVSS 4.0 assessment (base score 7.2/10) rates confidentiality impact as high; integrity and availability impact as low.

Published

CWE
CWE-89
CCR priority
35.3 /100 (P4)
CVSS 3.1
8.8 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.00498 · percentile 0.40727 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-62238.html