PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-70340 ThingsBoard CVE debrief

A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation of system messages and modification of trusted system-owned data, resulting in vertical privilege escalation and potential integrity violations. Organizations should review and apply the vendor's patch for ThingsBoard Professional Edition (PE) 4.21 and below. The CVE record was published on 2026-08-26T20:16:59.823Z and has not been modified since then. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM.

Vendor
ThingsBoard
Product
ThingsBoard Professional Edition (PE)
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-01
Advisory published
2026-08-26
Advisory updated
2026-09-01

Who should care

Organizations using ThingsBoard Professional Edition (PE) 4.21 and below should be aware of this vulnerability and take necessary actions to prevent potential integrity violations. This includes reviewing and applying the vendor's patch, restricting access to the Alarms comments functionality, and implementing additional logging and auditing to detect potential integrity violations. Operators, platform administrators, and security teams should review the vulnerability and take necessary actions to protect their systems.

Technical summary

A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation of system messages and modification of trusted system-owned data, resulting in vertical privilege escalation and potential integrity violations. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM.

Defensive priority

Organizations using ThingsBoard Professional Edition (PE) 4.21 and below should prioritize patching to prevent potential integrity violations.

Recommended defensive actions

  • Review and apply the vendor's patch for ThingsBoard Professional Edition (PE) 4.21 and below.
  • Restrict access to the Alarms comments functionality to authorized personnel only.
  • Monitor system-generated alarm comments for potential unauthorized modifications.
  • Implement additional logging and auditing to detect potential integrity violations.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE-2025-70340 record indicates a Broken Access Control vulnerability in ThingsBoard Professional Edition (PE) 4.21 and below. An authenticated customer user can manipulate API request parameters to create or modify system-generated alarm comments, allowing unauthorized impersonation of system messages and modification of trusted system-owned data.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-70340 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-70340

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-70340 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-70340

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.