Skip to content

Thingsboard

v4.3.1.3 Security

This release includes 29 security fixes for security teams reviewing exposed deployments.

Published 27d Home Automation
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 29 known CVEs

Topics

big-data cloud coap-server dashboards http iiot
+12 more
iot iot-analytics iot-framework iot-platform iot-solutions lwm2m-server microservices middleware mqtt snmp thingsboard visualization

Affected surfaces

auth rbac rce_ssrf

Summary

AI summary

Fixed multiple CVEs including CVE-2026-44705, CVE-2026-46625, and CVE-2026-45799 across UI, Core & Rule Engine, and Edge.

Full changelog

What's Changed

Security

  • Fixed CVE-2026-44705 and CVE-2026-46625 by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15721
  • Fixed CVE-2026-45799 by @ViacheslavKlimov in https://github.com/thingsboard/thingsboard/pull/15757
  • Fixed CVE-2026-44249, CVE-2026-44250, CVE-2026-44890, CVE-2026-44893, CVE-2026-45292, CVE-2026-45416, CVE-2026-45674, CVE-2026-46340, CVE-2026-47691, CVE-2026-48006, CVE-2026-48059, CVE-2026-50010, CVE-2026-50011 by @ViacheslavKlimov in https://github.com/thingsboard/thingsboard/pull/15795
  • Fixed CVE-2026-44705, CVE-2026-50171, CVE-2026-50170, CVE-2026-54267, CVE-2026-54266, CVE-2026-54290, CVE-2026-48779, CVE-2026-54268, CWE-426, CWE-494, CVE-2026-53571, CVE-2026-12143, CVE-2026-9277 by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15799

Core & Rule Engine

  • Integration with IoT Hub by @ikulikov in https://github.com/thingsboard/thingsboard/pull/15193
  • AI models: structured output support for more providers; fix Vertex AI location routing by @dskarzh in https://github.com/thingsboard/thingsboard/pull/15728
  • Prevented integer overflow in calculated field SUM output by @volodymyr-babak in https://github.com/thingsboard/thingsboard/pull/15620
  • Fixed queue prefix not applied in some cases causing orphaned topics by @AndriiLandiak in https://github.com/thingsboard/thingsboard/pull/15666
  • Fixed RPC call request rule node returning null body by @dashevchenko in https://github.com/thingsboard/thingsboard/pull/15662
  • Fixed permission check on alarm comment edit by @dashevchenko in https://github.com/thingsboard/thingsboard/pull/15715
  • Hardened device credentials validation by @dashevchenko in https://github.com/thingsboard/thingsboard/pull/15550
  • Fixed transport tenant-profile lock convoy under cold-cache reconnect storm by @ViacheslavKlimov in https://github.com/thingsboard/thingsboard/pull/15744

UI

  • Added help pages for html container by @pinkevmladchy in https://github.com/thingsboard/thingsboard/pull/15767
  • Fixed Switch Control widget hanging on one-way persistent RPC by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15711
  • Fixed no widgets shown in mobile view after state transition from divided layout by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15710
  • Fixed change Password button stays disabled when form is filled programmatically by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15701
  • Fixed sync highlight overlay scroll on Safari in string-pattern-autocomplete by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15754
  • Fixed Advanced Widget Style Editor rendering by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15803
  • Fixed dashboard logo stretch at full width by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15800
  • Fixed "Confirm exit" dialog appearing when the form was not changed by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15764
  • Added handler for WebGL unavailability in map widget by @mtsymbarov-del in https://github.com/thingsboard/thingsboard/pull/15640

Edge

  • Fixed edge event loss for kafka edges during sync by @AndriiLandiak in https://github.com/thingsboard/thingsboard/pull/15756

Full Changelog: https://github.com/thingsboard/thingsboard/compare/v4.3.1.2...v4.3.1.3

Security Fixes

  • CVE-2026-44705 — security vulnerability fixed
  • CVE-2026-46625 — security vulnerability fixed
  • CVE-2026-45799 — security vulnerability fixed
  • CVE-2026-44249 — security vulnerability fixed
  • CVE-2026-44250 — security vulnerability fixed
  • CVE-2026-44890 — security vulnerability fixed
  • CVE-2026-44893 — security vulnerability fixed
  • CVE-2026-45292 — security vulnerability fixed
  • CVE-2026-45416 — security vulnerability fixed
  • CVE-2026-45674 — security vulnerability fixed
  • CVE-2026-46340 — security vulnerability fixed
  • CVE-2026-47691 — security vulnerability fixed
  • CVE-2026-48006 — security vulnerability fixed
  • CVE-2026-48059 — security vulnerability fixed
  • CVE-2026-50010 — security vulnerability fixed
  • CVE-2026-50011 — security vulnerability fixed
  • CVE-2026-44705 (duplicate) — already listed
  • CVE-2026-50171 — security vulnerability fixed
  • CVE-2026-50170 — security vulnerability fixed
  • CVE-2026-54267 — security vulnerability fixed
  • CVE-2026-54266 — security vulnerability fixed
  • CVE-2026-54290 — security vulnerability fixed
  • CVE-2026-48779 — security vulnerability fixed
  • CVE-2026-54268 — security vulnerability fixed
  • CWE-426 — class vulnerability addressed
  • CWE-494 — class vulnerability addressed
  • CVE-2026-53571 — security vulnerability fixed
  • CVE-2026-12143 — security vulnerability fixed
  • CVE-2026-9277 — security vulnerability fixed

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Thingsboard

Get notified when new releases ship.

Sign up free

About Thingsboard

Open-source IoT Platform - Device management, data collection, processing and visualization.

All releases →

Related context

Beta — feedback welcome: [email protected]