A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation of system messages and modification of trusted system-owned data, resulting in vertical privilege escalation and potential integrity violations.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 20:16
Updated : 2026-09-09 16:04
NVD link : CVE-2025-70340
Mitre link : CVE-2025-70340
CVE.ORG link : CVE-2025-70340
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
