CVE-2026-24014Disclosure(apache / iotdb)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache iotdb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. This could allow arbitrary file write with the permissions of the IoTDB process. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • iotdb

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-07-06); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
iotdb

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-07-06: 4Mentions · 2026-07-08: 1Mentions · 2026-07-11: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-06: 4Technical Details · 2026-07-08: 1Technical Details · 2026-07-11: 107-0607-0807-11
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-07-064
Disclosure3General1
2026-07-081
General1
2026-07-111
Patch1
Full discourse6 posts
  • vulntoday@vulntoday
    Disclosure

    🔴 CRITICAL CVE-2026-24014 Arbitrary file write in Apache IoTDB DataNode (versions 1.3.3 up to but not including 2.0.8) allows attackers who can reach the internal DataNode RPC port to smuggle path-traversal sequences in an up… https://vuln.today/cve/CVE-2026-24014 #CVE #infosec

    Post summary

    The tweet announces the critical CVE‑2026‑24014, describing an arbitrary file write via path‑traversal in Apache IoTDB DataNode versions 1.3.3‑2.0.8, but provides no proof of exploitation or mitigation details.

    40070199
    23 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Three Apache IoTDB vulnerabilities include a critical path traversal (CVE-2026-24014) and an authentication bypass. Upgrade to 2.0.8 now. #ApacheIoTDB #PathTraversal #AuthBypass #CVE #IoTSecurity #InfoSec http://securityonline.info/apache-iotdb-vulnerabilities/

    Post summary

    Three Apache IoTDB vulnerabilities, including a critical path traversal and an authentication bypass, have been mitigated in version 2.0.8; users are advised to upgrade immediately.

    01040736
    12.9K followersView on X
  • Open Source Security mailing list@oss_security
    General

    Apache IoTDB CVE-2026-24012: DoS via Resource Exhaustion in Aggregation Query https://www.openwall.com/lists/oss-security/2026/07/06/10 CVE-2026-24013: Authentication Bypass via Forged SessionID in Thrift RPC https://www.openwall.com/lists/oss-security/2026/07/06/11 CVE-2026-24014: Path Traversal [...] Arbitrary File Write https://www.openwall.com/lists/oss-security/2026/07/06/12

    Post summary

    The text lists three Apache IoTDB CVEs with concise attack vectors but provides no PoC, exploit code, patch, or active exploitation details.

    00040578
    4.7K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🗂️ Apache IoTDB CVSS 9.8: path traversal in DataNode's internal RPC Trigger JAR upload lets attackers write arbitrary files. No auth needed if the RPC port is exposed. CVE-2026-24014 #Apache #infosec https://secalerts.co/vulnerability/CVE-2026-24014?utm_campaign=x https://t.co/0c77WtxHyp

    Post summary

    The tweet announces a CVSS 9.8 path traversal flaw (CVE-2026-24014) in Apache IoTDB’s internal RPC JAR upload that permits unauthenticated arbitrary file writes.

    00000105
    851 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-24014 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. I… https://www.cve.org/CVERecord?id=CVE-2026-24014 ----- Traducción: CVE-2026-24014 La … http://infoflow.cloud`

    Post summary

    The post is a straightforward CVE announcement for CVE‑2026‑24014, describing a path‑validation flaw in Apache IoTDB’s internal RPC trigger creation. No proof‑of‑concept, exploit, patch, or active‑exploitation details are provided.

    0000042
    92 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24014 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. I… https://www.cve.org/CVERecord?id=CVE-2026-24014

    Post summary

    The text announces CVE-2026-24014, highlighting a path‑validation flaw in Apache IoTDB’s DataNode RPC interface for trigger JAR uploads.

    00000862
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheiotdb---

Explore more