
🔓 Apache IoTDB CVSS 9.8: REST Basic Auth accepts stale cached credentials, enabling auth bypass via capture-replay. No privileges needed, fully remote. CVE-2026-28564 https://secalerts.co/vulnerability/CVE-2026-28564?utm_campaign=x https://t.co/08hLuZzv47
Post summary
Apache IoTDB’s CVE-2026-28564 is a CVSS 9.8 auth bypass vulnerability that allows remote attackers to reuse stale credentials without privileges; no PoC, exploit, or patch information is shared.
