Skip to content
iotdbPYSEC-2026-2081

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to w

Critical9.8CVE-2026-24014 · Published Jul 6, 2026 · updated Jul 8, 2026

Source advisory

Affected versions

PackageAffectedFixed in
apache-iotdb
PyPI
>= 1.3.3, < 2.0.82.0.8
Details and references

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. This could allow arbitrary file write with the permissions of the IoTDB process. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
the CVSS score
Also known as
CVE-2026-24014

More iotdb advisories

All
DateAdvisory
Jul 6Uncontrolled Resource Consumption vulnerability in Apache IoTDB.
CVE-2026-24012High7.5fixed in 2.0.8
Jul 6Authentication Bypass by Spoofing vulnerability in Apache IoTDB.
CVE-2026-24013Critical9.1fixed in 2.0.8
Sep 242025Apache IoTDB: Deserialization of untrusted Data
CVE-2025-48459Critical5.3fixed in 2.0.5
May 142025Apache IoTDB Discloses Sensitive Information via Log Files
CVE-2025-26864Mediumfixed in 1.3.4, 2.0.2
May 142025Apache IoTDB Vulnerable to Remote Code Execution
CVE-2024-24780Critical9.8fixed in 1.3.4
Jan 152024Remote Code Execution vulnerability in Apache IoTDB via UDF
CVE-2023-46226High9.8fixed in 1.3.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.