Executive brief
Apache IoTDB, a database designed for managing large amounts of time-series data, contains a security flaw that allows unauthorized users to bypass login requirements. By forging a session identifier, an attacker can trick the system into providing access to sensitive data without a valid password. This could lead to the unauthorized disclosure of proprietary sensor data or operational metrics stored within the database.
Technical details
An authentication bypass vulnerability exists in Apache IoTDB due to insufficient validation of the sessionId parameter within certain Thrift RPC query handlers. The root cause is a failure to strictly verify that a provided sessionId has undergone the standard openSession authentication process. A remote, unauthenticated attacker can exploit this by constructing malicious RPC requests with a forged sessionId to retrieve valid query results. This allows for unauthorized reading of time-series data. The issue is fixed in version 2.0.8.
Affected products
- Apache IoTDB 1.3.3 to 2.0.7
Timeline
- 2026-07-06: advisory: Initial disclosure of CVE-2026-24013
- 2026-07-06: patched: Version 2.0.8 released to address the vulnerability