Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
TDengine: Standard User permission unexpect
CVE-2026-62355
Description
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only permissions for non-database objects and show dnodes and create user were denied. This issue is fixed in version 3.4.1.15.
Affected products
1Patches
Vulnerability mechanics
References
1- github.com/taosdata/TDengine/security/advisories/GHSA-fmp7-rf4r-8q7pmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.