CVE-2026-28564: Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials
This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.
Users are recommended to upgrade to version 2.0.10, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache IoTDBto a version that resolves this vulnerability.Fixed in 2.0.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28564?
The severity of CVE-2026-28564 is critical, with a CVSS score of 9.8.
How do I fix CVE-2026-28564?
To fix CVE-2026-28564, upgrade Apache IoTDB to version 2.0.10 or later.
What is the impact of CVE-2026-28564?
CVE-2026-28564 can lead to insufficient session expiration and potential authentication bypass, allowing attackers to reuse stale cached credentials.
Which versions of Apache IoTDB are affected by CVE-2026-28564?
CVE-2026-28564 affects Apache IoTDB versions from 1.0.0 up to but not including 2.0.10.
How can attackers exploit CVE-2026-28564?
Attackers can exploit CVE-2026-28564 by capturing and replaying stale cached credentials to bypass authentication.