CVE-2026-24013General(apache / iotdb)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • iotdb

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-06); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
iotdb

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-06: 2Mentions · 2026-07-08: 1Technical Details · 2026-07-06: 2Technical Details · 2026-07-08: 107-0607-08
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-062
Disclosure1General1
2026-07-081
General1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    General

    Apache IoTDB CVE-2026-24012: DoS via Resource Exhaustion in Aggregation Query https://www.openwall.com/lists/oss-security/2026/07/06/10 CVE-2026-24013: Authentication Bypass via Forged SessionID in Thrift RPC https://www.openwall.com/lists/oss-security/2026/07/06/11 CVE-2026-24014: Path Traversal [...] Arbitrary File Write https://www.openwall.com/lists/oss-security/2026/07/06/12

    Post summary

    The snippet lists several new CVEs for Apache IoTDB with brief technical descriptions and links to Openwall advisories, but no exploit, PoC, patch, or exploitation activity is mentioned.

    00040578
    4.7K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-24013 Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can … https://www.cve.org/CVERecord?id=CVE-2026-24013 ----- Traducción: CVE-2026-24013 Omi… http://infoflow.cloud`

    Post summary

    The post introduces CVE‑2026‑24013, outlining an authentication bypass via sessionId spoofing in Apache IoTDB, but provides no information on PoC, exploitation tools, active attacks, or remediation.

    0000045
    92 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24013 Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can … https://www.cve.org/CVERecord?id=CVE-2026-24013

    Post summary

    The passage announces an authentication bypass vulnerability in Apache IoTDB caused by insufficient sessionId validation, but offers no PoC, exploit, or remediation details.

    00000805
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheiotdb---

Explore more