SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-62355

MEDIUM · CVSS 5.4 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

TDengine, an open-source time-series database for IoT devices, has a vulnerability that allows a Data Reader admin_user to execute the "create udf" command, bypassing intended read-only permissions for standard users. This could lead to unauthorized modifications and potential data integrity issues. Organizations using versions prior to 3.4.1.15 should prioritize upgrading to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62355
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%

Original NVD Description

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only permissions for non-database objects and show dnodes and create user were denied. This issue is fixed in version 3.4.1.15.