VYPR
Critical severity9.1OSV Advisory· Published Jul 6, 2026· Updated Jul 7, 2026

CVE-2026-24013

CVE-2026-24013

Description

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data.

This issue affects Apache IoTDB: from 1.3.3 before 2.0.8.

Users are recommended to upgrade to version 2.0.8, which fixes the issue.

Affected products

4
  • Apache/Iotdb4 versions
    cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:*range: >=1.3.3,<2.0.8
    • (no CPE)
    • (no CPE)range: >=1.3.3 <2.0.8
    • (no CPE)range: >=1.3.3 <2.0.8

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.