Loading market data...
← Back to CVE feed

CVE-2025-70340

UNKNOWN View on NVD ↗

Description

A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation of system messages and modification of trusted system-owned data, resulting in vertical privilege escalation and potential integrity violations.

Published: Aug 26, 2026 20:16 UTC Modified: Aug 26, 2026 20:16 UTC