Executive brief
ThingsBoard Professional Edition is an open-source IoT platform used to manage devices, collect data, and visualize system information. A vulnerability in the alarm comments feature allows authenticated users to impersonate system messages and modify trusted system data, potentially escalating privileges or tampering with critical alerts and audit trails.
Technical details
A broken access control vulnerability exists in ThingsBoard PE 4.21 and below in the alarm comments functionality. Authenticated customer users can manipulate API request parameters to create or modify system-generated alarm comments, bypassing authorization checks that should restrict such operations to the system only. This enables vertical privilege escalation and integrity violations through impersonation of system messages and modification of system-owned data. The vulnerability requires authentication but allows low-privileged users to perform actions restricted to higher privilege levels or system components.
Affected products
- ThingsBoard Professional Edition 4.21 and below
Timeline
- 2026-08-26: disclosed