CVE-2026-53676

HIGH

ThingsBoard - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Title source: rule
STIX 2.1

Description

ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).

Scores

CVSS v3 7.2
EPSS 0.0060
EPSS Percentile 44.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1321
Status published
Products (1)
ThingsBoard/ThingsBoard prior to v4.3.1.2
Published Jun 17, 2026
Tracked Since Jun 18, 2026