Critical severity9.1NVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
CVE-2026-40005
CVE-2026-40005
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API.
This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.
Users are recommended to upgrade to version 2.0.10, which fixes the issue.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.