CVE-2022-48341: Thingsboard

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.

Affected products

Published 2023-02-23. Last modified 2026-06-17.