Path traversal in Apache IoTDB - CVE-2026-24014

 

Path traversal in Apache IoTDB - CVE-2026-24014

Published: August 24, 2026


Vulnerability identifier: #VU144717
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24014
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write arbitrary files.

The vulnerability exists due to path traversal in DataNode internal RPC interface for creating Trigger instances when processing an uploaded Trigger JAR name. A remote attacker can supply a JAR name containing path traversal sequences to write arbitrary files.

Exploitation requires the internal DataNode RPC port to be exposed to an untrusted network.


Affected software

Apache IoTDB

How to mitigate CVE-2026-24014

Install security update from vendor's website.

Apache IoTDB - update to 2.0.8

External References

Related Security Bulletins