Vulnerability GHSA-49vv-25qx-mg44

High Risk
HIGH RISK
CVSS Score: 7.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 months ago
April 22, 2026 at 02:38 PM UTC
OpenRemote has Improper Access Control via updateUserRealmRoles function
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.22.0
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.22.0

Summary

OpenRemote has Improper Access Control via updateUserRealmRoles function

Details

Summary

A user who has write:admin in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including master. The handler uses the {realm} path segment when talking to the identity provider but does not check that the caller may administer that realm. This could result in a privilege escalation to master realm administrator if the attacker controls any user in master realm.

Details

In manager/src/main/java/org/openremote/manager/security/UserResourceImpl.java, there is no check to validate if the caller should be able to administer a realm they're trying to update.

    @Override
    public void updateUserRealmRoles(RequestParams requestParams, String realm, String userId, String[] roles) {
        try {
            identityService.getIdentityProvider().updateUserRealmRoles(
                realm,
                userId,
                roles);
        } catch (ClientErrorException ex) {
            ex.printStackTrace(System.out);
            throw new WebApplicationException(ex.getCause(), ex.getResponse().getStatus());
        } catch (Exception ex) {
            throw new WebApplicationException(ex);
        }
    }

PoC

  1. Create a new Keycloak realm other than master. Add a user and grant that user the OpenRemote client role write:admin. Remember the realm name (call it NEW_REALM).
  2. In Keycloak realm master, pick a low-privilege user (no admin realm role). Copy that user’s UUID (<master-user-uuid>).
  3. Authenticate as the user from step 1 and obtain a Bearer access token (<token>) for NEW_REALM.
  4. Replace placeholders and run:
curl -k -X PUT "https://<host>/api/<NEW_REALM>/user/master/userRealmRoles/<master-user-uuid>" \
  -H "Authorization: Bearer <token>" \
  -H "Content-Type: application/json" \
  -d '["admin"]'
  1. In the Keycloak Admin Console, realm master, that user, Role mapping. Confirm the admin realm role is assigned.

Impact

An attacker with the OpenRemote client role write:admin in any realm can call this API with {realm} set to another realm (for example master) and change Keycloak realm roles for users there. That can grant admin on master to a user UUID they target, which gives Keycloak administrator access for the master realm.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
2 months ago
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 and 1.25.0 GHSA-cgfv-jrfp-2r7v
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 and 1.25.0 GHSA-cgfv-jrfp-2r7v
High Risk
2 months ago
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.1 GHSA-xqr9-4wvv-gvch
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.1 GHSA-xqr9-4wvv-gvch
Medium Risk
2 months ago
OpenRemote read-only asset users can write predicted datapoints
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.0 GHSA-xj53-j257-hxvg
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.0 GHSA-xj53-j257-hxvg
Critical
3 months ago
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 GHSA-h3m5-97jq-qjrf
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 GHSA-h3m5-97jq-qjrf
High Risk
5 months ago
OpenRemote has XXE in Velbus Asset Import
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 GHSA-g24f-mgc3-jwwc
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 GHSA-g24f-mgc3-jwwc
View all vulnerabilities for these packages

Timeline

Published
5 months ago
April 22, 2026 at 02:38 PM UTC
Fixed (1.22.1)
Unknown
Unknown
Last Modified
4 months ago
May 05, 2026 at 04:00 PM UTC