CVE-2026-53676 Details
Description
ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).
A prototype pollution vulnerability has been identified in ThingsBoard, allowing for arbitrary code execution within a sandboxed context. This issue affects ThingsBoard versions prior to 4.3.1.2. The vulnerability can be exploited by users with tenant administrator privileges (TENANT_ADMIN) who are logged into the affected product.
Users are advised to update to the latest version of ThingsBoard. Instructions for upgrading can be found in the ThingsBoard Release Table.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 17, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/thingsboard/thingsboard/pull/15600 | [email protected] | Issue TrackingVendor |
| https://jvn.jp/en/jp/JVN16937365/ | [email protected] | AdvisoryRemedy |
| https://thingsboard.io/docs/releases/releases-table/ | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1321 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ThingsBoard | < 4.3.1.2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |
Volerion