VYPR

Apache IoTDB

by Apache

CVEs (1)

  • CVE-2026-24013CriJul 6, 2026
    risk 0.00cvss 9.1epss 0.01

    Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid…