Path traversal in Apache IoTDB - CVE-2026-24014
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to write arbitrary files.
The vulnerability exists due to path traversal in DataNode internal RPC interface for creating Trigger instances when processing an uploaded Trigger JAR name. A remote attacker can supply a JAR name containing path traversal sequences to write arbitrary files.
Exploitation requires the internal DataNode RPC port to be exposed to an untrusted network.