CVE-2026-24713Disclosure(apache / iotdb)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-917

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • iotdb

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
iotdb

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-09: 4Technical Details · 2026-03-09: 203-09
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-24713: Apache IoTDB: JEXL Expression Injection https://www.openwall.com/lists/oss-security/2026/03/09/4 CVE-2026-24015: Apache IoTDB: Insecure Default Configuration https://www.openwall.com/lists/oss-security/2026/03/09/5

    Post summary

    The text lists two Apache IoTDB vulnerabilities (CVE-2026-24713 and CVE-2026-24015), providing brief descriptions and URLs for further details but no actionable or exploit information.

    00011221
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24713 Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to… https://www.cve.org/CVERecord?id=CVE-2026-24713

    Post summary

    A new Apache IoTDB vulnerability (CVE-2026-24713) involving improper input validation has been disclosed, affecting specific pre‑1.3.7 and pre‑2.0.7 releases.

    00000115
    56.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-24713 🚨 Risk Level: Unknown 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-24713 #CVE-2026-24713 #CVE  #Apache #CyberSecurity #InfoSec https://t.co/ISKb6UPcKO

    Post summary

    A newly disclosed CVE affecting Apache is announced, with no details on exploitation, patch, or specific technical characteristics.

    0000038
    90 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-24713 CVE-2026-24713 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24713

    Post summary

    The provided text simply repeats the CVE identifier twice and supplies a URL, but no substantive details about the vulnerability, PoC, exploit, patch, or activity are included.

    0000053
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheiotdb---

Explore more