CVE-2026-40005

CVE-2026-40005: Apache IoTDB: Path Traversal in Pipe File Transfer Receiver

Vendor Apache Software Foundation
Product Apache IoTDB
Weakness CWE-22 · Path traversal
Published July 10, 2026
Last update July 10, 2026

CVSS base score

What the vulnerability does

01Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.

Key dates

02Disclosure timeline

July 10, 2026 CVE published
July 10, 2026 Record updated

Related vulnerabilities

04Related CVE