CVE-2026-53676: Thingsboard

High severity, CVSS 8.6. EPSS: 0.8% chance of exploitation in the next 30 days.

ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).

Affected products

  • Thingsboard Thingsboard: before v4.3.1.2 (fixed in v4.3.1.2)

Published 2026-06-17. Last modified 2026-06-22.