SB20260824130 - Multiple vulnerabilities in Apache IoTDB



SB20260824130 - Multiple vulnerabilities in Apache IoTDB

Published: August 24, 2026

Security Bulletin ID SB20260824130
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 88% Low 13%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 vulnerabilities.


1) Insufficient Session Expiration (CVE-ID: CVE-2026-28564)

CWE-ID: CWE-613 - Insufficient Session Expiration

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass authentication.

The vulnerability exists due to insufficient session expiration in REST Basic Authentication when processing captured cached credentials. A remote user can replay stale credentials to bypass authentication.


2) Path traversal (CVE-ID: CVE-2026-40005)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write arbitrary files.

The vulnerability exists due to path traversal in pipe file transfer receiver when handling file transfer requests. A remote attacker can use an unsafe API with a crafted pathname to write arbitrary files.


3) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-40006)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the IoTDB AirGap pipe receiver when processing raw TCP connections. A remote attacker can send a crafted length value to exhaust heap memory and cause a denial of service.

Only instances with pipe_air_gap_receiver_enabled=true are vulnerable.


4) Uncontrolled Recursion (CVE-ID: CVE-2026-40007)

CWE-ID: CWE-674 - Uncontrolled Recursion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled recursion in the AirGap receiver readLength method when parsing socket data containing repeated E-language prefixes. A remote attacker can send a stream of repeated E-language prefixes to cause a denial of service.

Only instances with pipe_air_gap_receiver_enabled=true are vulnerable.


5) Unsafe reflection (CVE-ID: CVE-2026-40008)

CWE-ID: CWE-470 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to instantiate arbitrary classes.

The vulnerability exists due to use of externally-controlled input to select classes or code in the pipe transfer RPC pipe processor when processing a fully qualified Java class name. A remote attacker can send a specially crafted class name to instantiate arbitrary classes.


6) Improper privilege management (CVE-ID: CVE-2026-40009)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges to full tree-path access.

The vulnerability exists due to improper privilege management in the user account handling logic when renaming an account to __internal_auditor. A remote user can rename their account to __internal_auditor to escalate privileges to full tree-path access.


7) Incorrect authorization (CVE-ID: CVE-2026-40452)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose last-value data.

The vulnerability exists due to improper access control in /rest/v2/fastLastQuery when handling authenticated requests. A remote user can send a request to the endpoint to disclose last-value data.


8) Input validation error (CVE-ID: CVE-2026-44630)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the RPC service when parsing crafted Thrift frames. A remote attacker can send a malformed Thrift frame to cause a denial of service.

The issue can trigger excessive memory allocation and terminate the process with an OutOfMemoryError.


Remediation

Install update from vendor's website.