VYPR
Unrated severityOSV Advisory· Published Jul 6, 2026· Updated Jul 6, 2026

Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC

CVE-2026-24013

Description

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data.

This issue affects Apache IoTDB: from 1.3.3 before 2.0.8.

Users are recommended to upgrade to version 2.0.8, which fixes the issue.

Affected products

2
  • Apache/IotdbOSV2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: from 1.3.3 before 2.0.8

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.