SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-40009

MEDIUM · CVSS 6.5 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Apache IoTDB versions 2.0.8 through 2.0.9 are vulnerable to improper privilege management, allowing authenticated users to escalate their access by renaming themselves to __internal_auditor, thereby gaining full tree-path access. This could lead to unauthorized data manipulation or exposure. Organizations using affected versions should prioritize upgrading to 2.0.10 to mitigate this risk.

CVE
CVE-2026-40009
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%
Apache

Original NVD Description

Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor. This issue affects Apache IoTDB: from 2.0.8 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.