---
id: CVE-2025-70340
title: >-
  A Broken Access Control vulnerability exists in ThingsBoard Professional
  Edition (PE) 4.21 and below, within the Alarms comments functionality
summary: >-
  A Broken Access Control vulnerability exists in ThingsBoard Professional
  Edition (PE) 4.21 and below, within the Alarms comments functionality. An
  authenticated customer user can manipulate the respective API request
  parameters to create…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-284
published: '2026-08-26'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:04:24.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-70340'
references:
  - url: 'https://github.com/thingsboard/thingsboard'
    label: cve@mitre.org
  - url: 'https://thingsboard.io/docs/releases/releases-table/v4-2-x/'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00221
epssPercentile: 0.11211
ingestedAt: '2026-09-09T16:14:05.516Z'
---

## Overview

A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation of system messages and modification of trusted system-owned data, resulting in vertical privilege escalation and potential integrity violations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
