CVE-2022-48341: Thingsboard
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.
Affected products
- Thingsboard Thingsboard: version 3.4.1 only
Published 2023-02-23. Last modified 2026-06-17.