CVE-2026-24013

CVE-2026-24013: Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC

Vendor Apache Software Foundation
Product Apache IoTDB
Weakness CWE-290
Published July 6, 2026
Last update July 6, 2026

CVSS base score

What the vulnerability does

01Description

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.

Key dates

02Disclosure timeline

July 6, 2026 CVE published
July 6, 2026 Record updated

Related vulnerabilities

04Related CVE