The predicted datapoint write endpoint allows users with only read:assets privileges to write predicted datapoints.
The endpoint:
PUT /api/{realm}/asset/predicted/{assetId}/{attributeName}
accepts write requests from users lacking write:assets.
The implementation appears to check READ_ASSETS while performing a write operation through:
assetPredictedDatapointService.updateValues(...)
A user was created with only:
read:assets
and without write:assets.
The following request succeeded:
PUT /api/master/asset/predicted/4Fr8Pcp7iDjrEmoSUFolvT/temperature
Request body:
[{"x":1779199999001,"y":1337}]
Response:
HTTP/2 204
Database verification confirmed the datapoint was written successfully:
entity_id: 4Fr8Pcp7iDjrEmoSUFolvT
attribute_name: temperature
value: 1337
Users with read-only asset permissions can modify predicted datapoints for assets.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed_at": "2026-07-06T16:52:35Z",
"nvd_published_at": null
}