Junglewise Threat Intelligence

CVE-2026-62355: TDengine improper privilege management in Cloud DB instances

CVE-2026-62355 · Severity: medium · CVSS 5.4 · Published 2026-07-15

Technologies: Taosdata TDengine. Vendors: TAOS Data.

Executive brief

TDengine is a specialized database used for managing data from Internet of Things (IoT) devices. A security flaw in certain versions allowed users with restricted 'Data Reader' permissions to perform administrative actions, such as creating user-defined functions, which should normally be blocked. This could allow a low-privileged user to modify system behavior or potentially disrupt operations, though it does not directly grant full administrative control over the entire database.

Technical details

A privilege management vulnerability (CWE-269) exists in TDengine Cloud DB instances. The root cause is an improper authorization check where users assigned the 'Data Reader' role—who should be restricted to read-only access for non-database objects—are permitted to execute 'create udf' commands. While other administrative actions like 'show dnodes' and 'create user' are correctly denied, the ability to create User-Defined Functions (UDFs) bypasses intended access controls. An authenticated attacker with low-level privileges can exploit this over the network to inject custom logic into the database environment. The issue is resolved in version 3.4.1.15.

Affected products

  • taosdata TDengine < 3.4.1.15

Timeline

  • 2026-06-26: advisory: Initial GitHub advisory published
  • 2026-07-15: disclosed: NVD publication date
  • 2026-07-15: patched: Fix confirmed in version 3.4.1.15

References

Related threats