OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration.
References
| Link | Resource |
|---|---|
| https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7v | Exploit Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openremote-sql-injection-via-crosstab-export | Third Party Advisory |
| https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7v | Exploit Mitigation Vendor Advisory |
Configurations
History
30 Jul 2026, 14:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openremote
Openremote openremote |
|
| CPE | cpe:2.3:a:openremote:openremote:*:*:*:*:*:*:*:* | |
| References | () https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7v - Exploit, Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openremote-sql-injection-via-crosstab-export - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
17 Jul 2026, 11:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7v - |
17 Jul 2026, 02:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-17 02:18
Updated : 2026-07-30 14:26
NVD link : CVE-2026-62238
Mitre link : CVE-2026-62238
CVE.ORG link : CVE-2026-62238
JSON object : View
Products Affected
openremote
- openremote
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
