CVE-2026-66013
OpenRemote Authentication Bypass in Console Registration API
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
OpenRemote technology has an authentication bypass vulnerability in its console registration API, allowing unauthenticated attackers to update existing assets, potentially redirecting or denying notifications.