CVE-2026-53676
Received Received - Intake
Prototype Pollution in ThingsBoard Leads to Code Execution

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: JPCERT/CC

Description
ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-18
AI Q&A
2026-06-18
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
thingsboard thingsboard *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in ThingsBoard is a prototype pollution issue that allows a user with tenant administrator privileges to manipulate the prototype of objects. This manipulation can lead to arbitrary code execution within a sandboxed context.

Impact Analysis

The vulnerability can allow an attacker with tenant administrator access to execute arbitrary code within the sandboxed environment of ThingsBoard. This could lead to unauthorized actions, data compromise, or further exploitation within the affected system.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53676. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart