Improper privilege management in Apache IoTDB - CVE-2026-40009
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges to full tree-path access.
The vulnerability exists due to improper privilege management in the user account handling logic when renaming an account to __internal_auditor. A remote user can rename their account to __internal_auditor to escalate privileges to full tree-path access.