Unsafe reflection in Apache IoTDB - CVE-2026-40008
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to instantiate arbitrary classes.
The vulnerability exists due to use of externally-controlled input to select classes or code in the pipe transfer RPC pipe processor when processing a fully qualified Java class name. A remote attacker can send a specially crafted class name to instantiate arbitrary classes.