Vulnerability Description
Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Iotdb | >= 1.3.3, < 2.0.8 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/6pwkgnqhbm56mvn309f87snm84s0b75yMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/06/11Mailing ListThird Party Advisory
FAQ
What is CVE-2026-24013?
CVE-2026-24013 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged s...
How severe is CVE-2026-24013?
CVE-2026-24013 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-24013?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Iotdb.