SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-40452

HIGH · CVSS 7.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Apache IoTDB versions 1.3.5 to 1.3.8 and 2.0.5 to 2.0.10 are vulnerable to an authorization bypass that allows unauthorized authenticated users to access sensitive last-value data through the /rest/v2/fastLastQuery endpoint. This flaw poses a significant risk to data confidentiality and integrity, making it critical for organizations using affected versions to prioritize upgrading to version 2.0.10 to mitigate potential data exposure.

CVE
CVE-2026-40452
Severity
HIGH
CVSS
7.5
EPSS
0.29%
Apache

Original NVD Description

Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. This issue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.