Privilege Escalation Vulnerability in ThingsBoard by ThingsBoard
CVE-2023-26462
8.1HIGH
What is CVE-2023-26462?
A vulnerability in ThingsBoard versions prior to 3.4.1 exposes hard-coded service credentials in an insecure manner, granting remote attackers the opportunity to perform privilege escalation. If they gain access to the application server or its source code, attackers can exploit this weakness to elevate their privileges and potentially access sensitive data or perform unauthorized actions within the system. It is critical for users to secure their applications and review access controls to mitigate this risk.
