
🪈 Apache IoTDB CVSS 9.8: the pipe processor deserializes a fully-qualified Java class name via RPC and instantiates it — no auth required. Arbitrary class instantiation at network level is as bad as it sounds. CVE-2026-40008 https://secalerts.co/vulnerability/CVE-2026-40008?utm_campaign=x https://t.co/Ucr0b0aRR3
Post summary
The tweet announces a high‑severity Apache IoTDB vulnerability (CVE‑2026‑40008) that allows unauthenticated arbitrary class instantiation via RPC, providing technical details but no exploit, mitigation, or evidence of active exploitation.

