PT-2026-43379 · Unknown · Thingsboard

Sunshinetoyou

·

Published

2026-05-26

·

Updated

2026-05-26

·

CVE-2026-9568

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ThingsBoard versions prior to 4.3.1.2
Description A code injection flaw exists in the YAML Handler component. The issue is located within the getGatewayDockerComposeFile() function of the '/api/v1/provision' endpoint. This allows a remote attacker to inject code, although the attack complexity is high and exploitation is considered difficult.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/api/v1/provision' endpoint or disable the getGatewayDockerComposeFile() function to minimize the risk of exploitation.

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9568

Affected Products

Thingsboard