CVE-2026-53676: Thingsboard
High severity, CVSS 8.6. EPSS: 0.8% chance of exploitation in the next 30 days.
ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).
Affected products
- Thingsboard Thingsboard: before v4.3.1.2 (fixed in v4.3.1.2)
Published 2026-06-17. Last modified 2026-06-22.