← Voltar à pesquisa de CVEs

CVE-2026-9568

ThingsBoard

Descrição

A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. This manipulation causes code injection. It is possible to initiate the attack remotely. The attack-s complexity is rated as high. The exploitation appears to be difficult. The project was informed of the problem early through a pull request but has not reacted yet.

CVSS 5EPSS 0.219%Risco 0.51
Ver fonte
Publicação
2026-05-26 19:16:34
Versões afetadas
<=4.3.1.1
Tipo
Core software
Última alteração
2026-07-23 11:10:00
Vetor
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L