SB20260824130 - Multiple vulnerabilities in Apache IoTDB
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Insufficient Session Expiration (CVE-ID: CVE-2026-28564)
CWE-ID: CWE-613 - Insufficient Session Expiration
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass authentication.
The vulnerability exists due to insufficient session expiration in REST Basic Authentication when processing captured cached credentials. A remote user can replay stale credentials to bypass authentication.
2) Path traversal (CVE-ID: CVE-2026-40005)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to write arbitrary files.
The vulnerability exists due to path traversal in pipe file transfer receiver when handling file transfer requests. A remote attacker can use an unsafe API with a crafted pathname to write arbitrary files.
3) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-40006)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the IoTDB AirGap pipe receiver when processing raw TCP connections. A remote attacker can send a crafted length value to exhaust heap memory and cause a denial of service.
Only instances with pipe_air_gap_receiver_enabled=true are vulnerable.
4) Uncontrolled Recursion (CVE-ID: CVE-2026-40007)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the AirGap receiver readLength method when parsing socket data containing repeated E-language prefixes. A remote attacker can send a stream of repeated E-language prefixes to cause a denial of service.
Only instances with pipe_air_gap_receiver_enabled=true are vulnerable.
5) Unsafe reflection (CVE-ID: CVE-2026-40008)
CWE-ID: CWE-470 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to instantiate arbitrary classes.
The vulnerability exists due to use of externally-controlled input to select classes or code in the pipe transfer RPC pipe processor when processing a fully qualified Java class name. A remote attacker can send a specially crafted class name to instantiate arbitrary classes.
6) Improper privilege management (CVE-ID: CVE-2026-40009)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges to full tree-path access.
The vulnerability exists due to improper privilege management in the user account handling logic when renaming an account to __internal_auditor. A remote user can rename their account to __internal_auditor to escalate privileges to full tree-path access.
7) Incorrect authorization (CVE-ID: CVE-2026-40452)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose last-value data.
The vulnerability exists due to improper access control in /rest/v2/fastLastQuery when handling authenticated requests. A remote user can send a request to the endpoint to disclose last-value data.
8) Input validation error (CVE-ID: CVE-2026-44630)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the RPC service when parsing crafted Thrift frames. A remote attacker can send a malformed Thrift frame to cause a denial of service.
The issue can trigger excessive memory allocation and terminate the process with an OutOfMemoryError.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=l38wpy7flvvfwv4rkps87l5z8gprnfy0
- https://iotdb.apache.org
- https://lists.apache.org/api/email.lua?id=zw2vkbmy5xkf5y8g237v81hrs4c6b5lq
- https://lists.apache.org/api/email.lua?id=rfpt7m9fvdrw37r3ow5omp2n914z6zqk
- https://lists.apache.org/api/email.lua?id=tr23kh6kp8drrsv8ypv1mqm4v5kyy23m
- https://lists.apache.org/api/email.lua?id=fm8cpvzbox2qqy99ztglm8wkk1nrg9ng
- https://lists.apache.org/api/email.lua?id=65hh7dh28rcxlzdzwdpt630321tr8b61
- https://lists.apache.org/api/email.lua?id=04j2l6dosyboor4o2gvrzbrcrpllmh95
- https://lists.apache.org/api/email.lua?id=tfsgd9whbq79lgjvdzj44hw0fhsofly8