Vulnerability GHSA-xj53-j257-hxvg

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
July 06, 2026 at 04:52 PM UTC
OpenRemote read-only asset users can write predicted datapoints
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.0
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.0

Summary

OpenRemote read-only asset users can write predicted datapoints

Details

Summary

The predicted datapoint write endpoint allows users with only read:assets privileges to write predicted datapoints.

The endpoint:

PUT /api/{realm}/asset/predicted/{assetId}/{attributeName}

accepts write requests from users lacking write:assets.

The implementation appears to check READ_ASSETS while performing a write operation through:

assetPredictedDatapointService.updateValues(...)

PoC

A user was created with only:

read:assets

and without write:assets.

The following request succeeded:

PUT /api/master/asset/predicted/4Fr8Pcp7iDjrEmoSUFolvT/temperature

Request body:

[{"x":1779199999001,"y":1337}]

Response:

HTTP/2 204

Database verification confirmed the datapoint was written successfully:

entity_id: 4Fr8Pcp7iDjrEmoSUFolvT
attribute_name: temperature
value: 1337

Impact

Users with read-only asset permissions can modify predicted datapoints for assets.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
2 months ago
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 and 1.25.0 GHSA-cgfv-jrfp-2r7v
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 and 1.25.0 GHSA-cgfv-jrfp-2r7v
High Risk
2 months ago
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.1 GHSA-xqr9-4wvv-gvch
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.24.1 GHSA-xqr9-4wvv-gvch
Critical
3 months ago
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 GHSA-h3m5-97jq-qjrf
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.23.1 GHSA-h3m5-97jq-qjrf
High Risk
5 months ago
OpenRemote has Improper Access Control via updateUserRealmRoles function
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.22.0 GHSA-49vv-25qx-mg44
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 - 1.22.0 GHSA-49vv-25qx-mg44
High Risk
5 months ago
OpenRemote has XXE in Velbus Asset Import
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 GHSA-g24f-mgc3-jwwc
1.4.0 - 1.10.0 and 1.12.0 - 1.12.1 and 1.12.3 - 1.14.0 and 1.16.1 and 1.18.0 - 1.19.0 and 1.21.0 GHSA-g24f-mgc3-jwwc
View all vulnerabilities for these packages

Timeline

Published
2 months ago
July 06, 2026 at 04:52 PM UTC
Fixed (1.24.1)
Unknown
Unknown
Last Modified
2 months ago
July 06, 2026 at 05:11 PM UTC