Aller au contenu

Fiche vulnérabilité

CVE-2026-62238 : faille élevée openremote openremote (CVSS 8.8)

Description

OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
17 juil. 2026
Dernière mise à jour
30 juil. 2026

Produits concernés

  • openremote openremote

Références

Rechercher une autre vulnérabilité dans la base CVE