Skip to content
iotdbPYSEC-2026-2080

Authentication Bypass by Spoofing vulnerability in Apache IoTDB.

Critical9.1CVE-2026-24013 · Published Jul 6, 2026 · updated Jul 8, 2026

Source advisory

Affected versions

PackageAffectedFixed in
apache-iotdb
PyPI
>= 1.3.3, < 2.0.82.0.8
Details and references

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
the CVSS score
Also known as
CVE-2026-24013

More iotdb advisories

All
DateAdvisory
Jul 6Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
CVE-2026-24012High7.5fixed in 2.0.8
Jul 6Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to w
CVE-2026-24014Critical9.8fixed in 2.0.8
Sep 242025Apache IoTDB: Deserialization of untrusted Data
CVE-2025-48459Critical5.3fixed in 2.0.5
May 142025Apache IoTDB Discloses Sensitive Information via Log Files
CVE-2025-26864Mediumfixed in 1.3.4, 2.0.2
May 142025Apache IoTDB Vulnerable to Remote Code Execution
CVE-2024-24780Critical9.8fixed in 1.3.4
Jan 152024Remote Code Execution vulnerability in Apache IoTDB via UDF
CVE-2023-46226High9.8fixed in 1.3.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.