Medium severity6.5NVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
CVE-2026-40009
CVE-2026-40009
Description
Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor.
This issue affects Apache IoTDB: from 2.0.8 before 2.0.10.
Users are recommended to upgrade to version 2.0.10, which fixes the issue.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.