CVE-2026-40009

CVE-2026-40009: Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor

Vendor Apache Software Foundation
Product Apache IoTDB
Weakness CWE-269
Published July 10, 2026
Last update July 10, 2026

CVSS base score

What the vulnerability does

01Description

Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. This issue affects Apache IoTDB: from 2.0.8 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.

Key dates

02Disclosure timeline

July 10, 2026 CVE published
July 10, 2026 Record updated

Related vulnerabilities

04Related CVE