iotdbPYSEC-2026-2080
Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
Critical9.1CVE-2026-24013 · Published Jul 6, 2026 · updated Jul 8, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-iotdb PyPI | >= 1.3.3, < 2.0.8 | 2.0.8 |
Details and references
Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the CVSS score
- Also known as
- CVE-2026-24013
More iotdb advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 6 | Uncontrolled Resource Consumption vulnerability in Apache IoTDB. CVE-2026-24012High7.5fixed in 2.0.8 | High7.5 | 2.0.8 |
| Jul 6 | Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to w CVE-2026-24014Critical9.8fixed in 2.0.8 | Critical9.8 | 2.0.8 |
| Sep 242025 | Apache IoTDB: Deserialization of untrusted Data CVE-2025-48459Critical5.3fixed in 2.0.5 | Critical5.3 | 2.0.5 |
| May 142025 | Apache IoTDB Discloses Sensitive Information via Log Files CVE-2025-26864Mediumfixed in 1.3.4, 2.0.2 | Medium | 1.3.4, 2.0.2 |
| May 142025 | Apache IoTDB Vulnerable to Remote Code Execution CVE-2024-24780Critical9.8fixed in 1.3.4 | Critical9.8 | 1.3.4 |
| Jan 152024 | Remote Code Execution vulnerability in Apache IoTDB via UDF CVE-2023-46226High9.8fixed in 1.3.0 | High9.8 | 1.3.0 |