{"id":"CVE-2026-53676","details":"ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).","modified":"2026-07-15T01:49:06.948869561Z","published":"2026-06-17T22:53:56.122Z","database_specific":{"cna_assigner":"jpcert","cwe_ids":["CWE-1321"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53676.json"},"references":[{"type":"WEB","url":"https://jvn.jp/en/jp/JVN16937365/"},{"type":"WEB","url":"https://thingsboard.io/docs/releases/releases-table/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53676.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53676"},{"type":"FIX","url":"https://github.com/thingsboard/thingsboard/pull/15600"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/thingsboard/thingsboard","events":[{"introduced":"c37fb50952db983aed707c5d48efed72ba749c89"},{"last_affected":"c37fb50952db983aed707c5d48efed72ba749c89"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"prior to v4.3.1.2"},{"last_affected":"prior to v4.3.1.2"}]}}],"versions":["prior to v4.3.1.2","v4.3.1.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53676.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}