CVE-2026-36537: Critical severity ThingsBoard ThingsBoard vulnerability

Published Jun 15, 2026
·
Updated

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/code/ endpoint. By manipulating the email address in this JSON object, a remote attacker can bypass authentication and gain full access to any existing user account on the platform without possessing the target user's credentials. This results in a complete account takeover.

Affected Software

1 affected component
ThingsBoard ThingsBoard=4.3.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Stop accepting or trusting the client-supplied 'user' JSON parameter on /login/oauth2/code. Validate identity server-side using the OAuth provider's assertions (e.g., verify ID token signature and claims) and map accounts based on provider-issued identifiers rather than any email or identity data supplied by the client.

    ThingsBoard /login/oauth2/code endpoint trust_user_parameter = false
  2. Configuration

    Temporarily disable the OAuth authorization-code login flow (/login/oauth2/code) until an upstream fix or patch is applied to prevent authentication bypass via the 'user' parameter.

    ThingsBoard OAuth2 authorization code flow authorization_code_exchange = disabled (temporary)
  3. Compensating control

    Deploy WAF/reverse-proxy rules to block or inspect requests to /login/oauth2/code that include a client-supplied 'user' parameter or manipulated email values. Where possible, restrict access to the endpoint to trusted IP ranges or internal networks until the issue is remediated.

  4. Operational

    Assume potential account takeover: review access logs for suspicious activity, revoke active sessions and OAuth tokens for impacted accounts, force password resets and re-authentication for users as appropriate, and rotate any credentials or API keys that may have been exposed.

Event History

Jun 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-36537?

CVE-2026-36537 has a critical severity rating of 9.8 according to the CVSS 3.1 scoring system.

2

How do I fix CVE-2026-36537?

To fix CVE-2026-36537, upgrade to the latest version of ThingsBoard that addresses the authentication bypass vulnerability.

3

What kind of attack can occur due to CVE-2026-36537?

CVE-2026-36537 allows for authentication bypass during the OAuth authorization code exchange, enabling unauthorized access to user accounts.

4

Which version of ThingsBoard is affected by CVE-2026-36537?

ThingsBoard v4.3.0.1 is the affected version that contains the vulnerability CVE-2026-36537.

5

What is the impact of CVE-2026-36537 on data confidentiality and integrity?

CVE-2026-36537 can lead to a compromise in data confidentiality, integrity, and availability due to unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203