


Perceptive Security
SOC/SIEM Consultancy

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit …
Published:
21 april 2026 om 22:00:00
Alert date:
22 april 2026 om 22:11:22
Source:
nvd.nist.gov
Mobile & IoT
OpenRemote, an open-source IoT platform, contains an XML External Entity (XXE) vulnerability in its Velbus asset import functionality prior to version 1.22.0. The vulnerability allows authenticated users to exploit XML parsing without proper XXE hardening, potentially leading to server-side file disclosure and Server-Side Request Forgery (SSRF) attacks. The exploitation is limited to files under 1023 characters. Version 1.22.0 addresses this security issue.
Technical details
Mitigation steps:
Affected products:
OpenRemote
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40882
https://github.com/openremote/openremote/security/advisories/GHSA-g24f-mgc3-jwwc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
