Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to w
Critical9.8CVE-2026-24014 · Published Jul 6, 2026 · updated Jul 8, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-iotdb PyPI | >= 1.3.3, < 2.0.8 | 2.0.8 |
Details and references
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. This could allow arbitrary file write with the permissions of the IoTDB process. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the CVSS score
- Also known as
- CVE-2026-24014
More iotdb advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 6 | Uncontrolled Resource Consumption vulnerability in Apache IoTDB. CVE-2026-24012High7.5fixed in 2.0.8 | High7.5 | 2.0.8 |
| Jul 6 | Authentication Bypass by Spoofing vulnerability in Apache IoTDB. CVE-2026-24013Critical9.1fixed in 2.0.8 | Critical9.1 | 2.0.8 |
| Sep 242025 | Apache IoTDB: Deserialization of untrusted Data CVE-2025-48459Critical5.3fixed in 2.0.5 | Critical5.3 | 2.0.5 |
| May 142025 | Apache IoTDB Discloses Sensitive Information via Log Files CVE-2025-26864Mediumfixed in 1.3.4, 2.0.2 | Medium | 1.3.4, 2.0.2 |
| May 142025 | Apache IoTDB Vulnerable to Remote Code Execution CVE-2024-24780Critical9.8fixed in 1.3.4 | Critical9.8 | 1.3.4 |
| Jan 152024 | Remote Code Execution vulnerability in Apache IoTDB via UDF CVE-2023-46226High9.8fixed in 1.3.0 | High9.8 | 1.3.0 |