Executive brief
TDengine is a specialized database used for managing data from Internet of Things (IoT) devices. A security flaw in certain versions allowed users with restricted 'Data Reader' permissions to perform administrative actions, such as creating user-defined functions, which should normally be blocked. This could allow a low-privileged user to modify system behavior or potentially disrupt operations, though it does not directly grant full administrative control over the entire database.
Technical details
A privilege management vulnerability (CWE-269) exists in TDengine Cloud DB instances. The root cause is an improper authorization check where users assigned the 'Data Reader' role—who should be restricted to read-only access for non-database objects—are permitted to execute 'create udf' commands. While other administrative actions like 'show dnodes' and 'create user' are correctly denied, the ability to create User-Defined Functions (UDFs) bypasses intended access controls. An authenticated attacker with low-level privileges can exploit this over the network to inject custom logic into the database environment. The issue is resolved in version 3.4.1.15.
Affected products
- taosdata TDengine < 3.4.1.15
Timeline
- 2026-06-26: advisory: Initial GitHub advisory published
- 2026-07-15: disclosed: NVD publication date
- 2026-07-15: patched: Fix confirmed in version 3.4.1.15