This release includes 26 security fixes for security teams reviewing exposed deployments.
Published 27d
Home Automation
✓ No known CVEs patched
This release patches 26 known CVEs
Topics
big-data
cloud
coap-server
dashboards
http
iiot
+12 more
iot
iot-analytics
iot-framework
iot-platform
iot-solutions
lwm2m-server
microservices
middleware
mqtt
snmp
thingsboard
visualization
Affected surfaces
auth
rbac
deps
Summary
AI summaryMultiple CVEs fixed and enhancements across Core & Rule Engine, UI, and Edge modules.
Full changelog
What's Changed
Security
- Fixed CVE-2026-44705 and CVE-2026-46625 by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15721
- Fixed CVE-2026-45799 by @ViacheslavKlimov in https://github.com/thingsboard/thingsboard/pull/15757
- Fixed CVE-2026-44249, CVE-2026-44250, CVE-2026-44890, CVE-2026-44893, CVE-2026-45292, CVE-2026-45416, CVE-2026-45674, CVE-2026-46340, CVE-2026-47691, CVE-2026-48006, CVE-2026-48059, CVE-2026-50010, CVE-2026-50011 by @ViacheslavKlimov in https://github.com/thingsboard/thingsboard/pull/15795
- Fixed CVE-2026-44705, CVE-2026-50171, CVE-2026-50170, CVE-2026-54267, CVE-2026-54266, CVE-2026-54290, CVE-2026-48779, CVE-2026-54268, CWE-426, CWE-494, CVE-2026-53571, CVE-2026-12143, CVE-2026-9277 by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15799
Core & Rule Engine
- Integration with IoT Hub by @ikulikov in https://github.com/thingsboard/thingsboard/pull/15193
- AI models: structured output support for more providers; fix Vertex AI location routing by @dskarzh in https://github.com/thingsboard/thingsboard/pull/15728
- Prevented integer overflow in calculated field SUM output by @volodymyr-babak in https://github.com/thingsboard/thingsboard/pull/15620
- Fixed queue prefix not applied in some cases causing orphaned topics by @AndriiLandiak in https://github.com/thingsboard/thingsboard/pull/15666
- Fixed RPC call request rule node returning null body by @dashevchenko in https://github.com/thingsboard/thingsboard/pull/15662
- Fixed permission check on alarm comment edit by @dashevchenko in https://github.com/thingsboard/thingsboard/pull/15715
- Hardened device credentials validation by @dashevchenko in https://github.com/thingsboard/thingsboard/pull/15550
- Fixed transport tenant-profile lock convoy under cold-cache reconnect storm by @ViacheslavKlimov in https://github.com/thingsboard/thingsboard/pull/15744
UI
- Added help pages for html container by @pinkevmladchy in https://github.com/thingsboard/thingsboard/pull/15767
- Fixed Switch Control widget hanging on one-way persistent RPC by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15711
- Fixed no widgets shown in mobile view after state transition from divided layout by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15710
- Fixed change Password button stays disabled when form is filled programmatically by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15701
- Fixed Advanced Widget Style Editor rendering by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15803
- Fixed dashboard logo stretch at full width by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15800
- Added handler for WebGL unavailability in map widget by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15640
Edge
- Fixed edge event loss for kafka edges during sync by @AndriiLandiak in https://github.com/thingsboard/thingsboard/pull/15756
Full Changelog: https://github.com/thingsboard/thingsboard/compare/v4.2.2.2...v4.2.2.3
Security Fixes
- CVE-2026-44705 — fixed multiple times
- CVE-2026-46625 — fixed
- CVE-2026-45799 — fixed
- CVE-2026-44249, CVE-2026-44250, CVE-2026-44890, CVE-2026-44893, CVE-2026-45292, CVE-2026-45416, CVE-2026-45674, CVE-2026-46340, CVE-2026-47691, CVE-2026-48006, CVE-2026-48059, CVE-2026-50010, CVE-2026-50011 — fixed
- CVE-2026-50171, CVE-2026-50170, CVE-2026-54267, CVE-2026-54266, CVE-2026-54290, CVE-2026-48779, CVE-2026-54268, CWE-426, CWE-494, CVE-2026-53571, CVE-2026-12143, CVE-2026-9277 — fixed
- CVE-2026-44250
- CVE-2026-44890
- CVE-2026-44893
- CVE-2026-45292
- CVE-2026-45416
- CVE-2026-45674
- CVE-2026-46340
- CVE-2026-47691
- CVE-2026-48006
- CVE-2026-48059
- CVE-2026-50010
- CVE-2026-50011
- CVE-2026-50170
- CVE-2026-54267
- CVE-2026-54266
- CVE-2026-54290
- CVE-2026-48779
- CVE-2026-54268
- CVE-2026-53571
- CVE-2026-12143
- CVE-2026-9277
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Thingsboard
Open-source IoT Platform - Device management, data collection, processing and visualization.
Related context
Related tools
Beta — feedback welcome: [email protected]