PT-2026-55880 · Apache · Apache Iotdb

·

CVE-2026-24014

·

Published

2026-07-06

·

Updated

2026-07-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache IoTDB versions 1.3.3 through 2.0.7
Description The internal RPC interface of the Apache IoTDB DataNode used for creating Trigger instances fails to sufficiently validate the name of the uploaded Trigger JAR when building a file path. If the internal DataNode RPC port is exposed to an untrusted network, an attacker can use path traversal sequences in the JAR name to write files outside the designated Trigger installation directory. This allows for arbitrary file write operations with the permissions of the IoTDB process.
Recommendations Upgrade to version 2.0.8.

Exploit

Fix

Unrestricted File Upload

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24014
PYSEC-2026-2081

Affected Products

Apache Iotdb