Executive brief
Apache IoTDB is a database designed for managing large amounts of Internet of Things (IoT) data. A security flaw in its internal communication interface allows an attacker to bypass file storage restrictions if the system's internal ports are exposed to the network. This could allow an attacker to write malicious files to the server, potentially leading to a full system compromise or data loss.
Technical details
A path traversal vulnerability exists in the Apache IoTDB DataNode's internal RPC interface. The root cause is insufficient validation of the Trigger JAR filename during the creation of Trigger instances, which is used to construct a local file path. If the internal DataNode RPC port is accessible over the network, an attacker can provide a filename containing traversal sequences (e.g., ../) to write arbitrary files outside the designated trigger directory. This exploit grants the attacker the ability to write files with the same privileges as the IoTDB process. The issue is resolved in version 2.0.8.
Affected products
- Apache IoTDB 1.3.3 to 2.0.7
Timeline
- 2026-07-06: disclosed
- 2026-07-06: advisory