CVE-2026-9568 PUBLISHED

ThingsBoard YAML provision getGatewayDockerComposeFile code injection

Assigner: VulDB
Reserved: 26.05.2026 Published: 26.05.2026 Updated: 27.05.2026

A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. This manipulation causes code injection. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitation appears to be difficult. The project was informed of the problem early through a pull request but has not reacted yet.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 2.3

Product Status

Vendor n/a
Product ThingsBoard
Versions
  • Version 4.3.1.0 is affected
  • Version 4.3.1.1 is affected

Credits

  • sunshinetoyou (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Code Injection CWE
  • Injection CWE