Critical severity9.8NVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
CVE-2026-28564
CVE-2026-28564
Description
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials
This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.
Users are recommended to upgrade to version 2.0.10, which fixes the issue.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.