CVE-2026-40008Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads a fully qualified Java class name and instantiates it using Class.forName().newInstance() without any validation or allowlisting. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-470

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-10: 2Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 207-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • SecAlerts@SecAlertsCo
    Disclosure

    🪈 Apache IoTDB CVSS 9.8: the pipe processor deserializes a fully-qualified Java class name via RPC and instantiates it — no auth required. Arbitrary class instantiation at network level is as bad as it sounds. CVE-2026-40008 https://secalerts.co/vulnerability/CVE-2026-40008?utm_campaign=x https://t.co/Ucr0b0aRR3

    Post summary

    The tweet announces a high‑severity Apache IoTDB vulnerability (CVE‑2026‑40008) that allows unauthenticated arbitrary class instantiation via RPC, providing technical details but no exploit, mitigation, or evidence of active exploitation.

    0000087
    855 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Apache IoTDB Unsafe Reflection in Pipe Processor (CVE-2026-40008) Apache IoTDB's pipe processor reads a fully qualified Java class name and instantiates it via Class.forName().newInstance() with no validation or allowlisting. An attacker who controls that class name can force instantiation of arbitrary classes on the classpath. With a suitable gadget class, that unsafe reflection can lead to code execution and full compromise of the IoTDB process. CISA-ADP scores it CVSS 9.8 and automatable; real exploitability depends on who can configure pipe processors and which classes are reachable on the classpath. 👉Upgrade Apache IoTDB to 2.0.10.

    Post summary

    Apache IoTDB’s Pipe Processor is vulnerable to unsafe reflection that can lead to arbitrary code execution; upgrading to version 2.0.10 mitigates the issue.

    0000080
    246 followersView on X

Explore more