9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
CVE-2026-39842: OpenRemote Expression Injection RCE in Rules Engine TL;DR Critical remote code execution vulnerability in OpenRemote's Rules Engine allows authenticated users with write:rules role to execute arbitrary code on the server with root...
Basic Information
ID
578EF6BD-C364-5AE8-B4DF-72589504AEB5
Published
Apr 17, 2026 at 09:36
Modified
Apr 17, 2026 at 09:37