# CVE-2026-41166

> Vulnerability · severity: **HIGH** (CVSS 7).

## Description

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segment when talking to the identity provider but does not check that the caller may administer that realm. This could result in a privilege escalation to `master` realm administrator if the attacker controls any user in `master` realm. Version 1.22.1 fixes the issue.

## Key facts

- **CVE ID:** CVE-2026-41166
- **Published:** 2026-04-22
- **CVSS severity:** HIGH
- **CVSS base score:** 7
- **CWE codes:** CWE-284

## Affected products

- `openremote:openremote`

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-41166

## Citation

> AI Analytics. CVE-2026-41166. Retrieved 2026-08-09 from https://api.ai-analytics.org/cve/CVE-2026-41166. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*