Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xj53-j257-hxvg | OpenRemote read-only asset users can write predicted datapoints |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue. | |
| Title | OpenRemote read-only asset users can write predicted datapoints | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-11T20:44:13.314Z
Reserved: 2026-05-30T02:43:33.105Z
Link: CVE-2026-49439
No data.
Status : Received
Published: 2026-09-11T21:17:10.370
Modified: 2026-09-11T21:17:10.370
Link: CVE-2026-49439
No data.
OpenCVE Enrichment
Updated: 2026-09-12T06:15:04Z
-
CWE-862
Missing Authorization
Github GHSA