SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-24014

CRITICAL · CVSS 9.8 EPSS 0.58%

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

The Apache IoTDB DataNode is vulnerable due to inadequate validation of the uploaded Trigger JAR name, allowing attackers to exploit path traversal sequences to write files outside the designated installation directory. This critical vulnerability could lead to arbitrary file writes with the permissions of the IoTDB process, posing significant risks to system integrity and confidentiality. Organizations using affected versions of Apache IoTDB (1.3.3 to 2.0.7) should prioritize upgrading to version 2.0.8 to mitigate this risk.

CVE
CVE-2026-24014
Severity
CRITICAL
CVSS
9.8
EPSS
0.58%
Apache

Original NVD Description

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. This could allow arbitrary file write with the permissions of the IoTDB process. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)