CVE-2026-39842Disclosure(openremote / openremote)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch openremote openremote systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-supplied scripts via Nashorn's ScriptEngine.eval() without sandboxing, class filtering, or access restrictions, and the authorization check in RulesResourceImpl only restricts Groovy rules to superusers while leaving JavaScript rules unrestricted for any user with the write:rules role. Additionally, the Groovy rules engine has a GroovyDenyAllFilter security filter that is defined but never registered, as the registration code is commented out, rendering the SandboxTransformer ineffective for superuser-created Groovy rules. A non-superuser attacker with the write:rules role can create JavaScript rulesets that execute with full JVM access, enabling remote code execution as root, arbitrary file read, environment variable theft including database credentials, and complete multi-tenant isolation bypass to access data across all realms. This issue has been fixed in version 1.22.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-917

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openremote

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-15)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openremote

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-14: 1Mentions · 2026-04-15: 3PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-15: 2Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 304-1404-15
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-153
Disclosure2Patch1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    OpenRemote CVE-2026-39842 is a critical CVSS 10 flaw allowing RCE via JavaScript and Groovy injection. Secure your IoT assets—upgrade to v1.22.0 now! #OpenRemote #IoTSecurity #RCE #InfoSec #CyberSecurity #PatchNow #CVE202639842 https://securityonline.info/openremote-cvss-10-vulnerability-iot-security-rce/ https://t.co/tRxReSAhPo

    Post summary

    A critical RCE vulnerability (CVE-2026-39842) in OpenRemote is highlighted, and users are urged to patch by upgrading to version 1.22.0.

    05076784
    12.3K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39842: OpenRemote is Vulnerable to Expr... Nashorn eval() with zero sandboxing plus commented-out Groovy filters = instant root RCE for any user with write:rules ... https://zerodaysignal.com/vulnerability/CVE-2026-39842 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-39842, highlighting a root RCE via Nashorn eval() with no sandboxing and providing a link that likely contains details or a PoC.

    0000175
    218 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39842 OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbi… https://www.cve.org/CVERecord?id=CVE-2026-39842

    Post summary

    The message announces two expression‑injection flaws in OpenRemote’s rules engine for versions 1.21.0 and earlier, providing basic technical details but no PoC, exploit, patch, or active exploitation evidence.

    0000061
    57.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An Expression Injection vulnerability (CVE-2026-39842) has been identified in `OpenRemote`, potentially allowing for arbitrary code execution. Monitor official `OpenRemote` advisories for patch availability. #OpenRemote #InfoSec #Vulnerability https://www.pulsepatch.io/posts/cve-2026-39842-openremote-expression-injection

    Post summary

    CVE-2026-39842 in OpenRemote is an expression injection flaw that could allow arbitrary code execution; users are advised to monitor official advisories for patches.

    0000034
    12 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenremoteopenremote---

Explore more