
CVE-2026-41166 OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to upda… https://www.cve.org/CVERecord?id=CVE-2026-41166
Post summary
A vulnerability in OpenRemote prior to version 1.22.1 allows privileged users to use the Manager API for potentially malicious updates; upgrading to 1.22.1 mitigates the issue.
