Impact
The issue is a broken access control vulnerability in the alarms comments feature of ThingsBoard Professional Edition version 4.21 and earlier. An authenticated customer user can manipulate API request parameters to create or modify system‑generated alarm comments, allowing the attacker to impersonate system messages and alter trusted alarm data. This leads to vertical privilege escalation and potential integrity violations of alarm data.
Affected Systems
All deployments of ThingsBoard Professional Edition (PE) 4.21 or earlier are affected. The vulnerability applies to the Alarms comments functionality and impacts any installation where that API is enabled and users have standard customer privileges.
Risk and Exploitability
Exploitation requires only an authenticated customer account; the description does not specify whether the attack must be local or remote, so the vector is inferred as either. No EPSS score is available and the flaw is not listed in CISA’s KEV catalog, indicating no known public exploitation at this time. Nevertheless, because the flaw permits modification of system‑generated data, the potential impact on data integrity is high, and the risk to affected deployments remains significant until a vendor patch restores proper authorization controls.
OpenCVE Enrichment