CVE-2026-40005: Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API.
This issue affects Apache IoTDB: from 1.0.0 before 2.0.10.
Users are recommended to upgrade to version 2.0.10, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache IoTDBto a version that resolves this vulnerability.Fixed in 2.0.10Patch CVE-2026-40005
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40005?
CVE-2026-40005 has a critical severity rating of 9.1 according to the CVSS 3.1 scoring system.
How do I fix CVE-2026-40005?
To fix CVE-2026-40005, upgrade Apache IoTDB to version 2.0.10 or later.
What types of systems are affected by CVE-2026-40005?
CVE-2026-40005 affects Apache IoTDB versions from 1.0.0 before 2.0.10.
What type of vulnerability is CVE-2026-40005?
CVE-2026-40005 is a Path Traversal vulnerability allowing file writing to unauthorized directories.
What could an attacker achieve with CVE-2026-40005?
An attacker exploiting CVE-2026-40005 can write arbitrary files wherever the IoTDB process has write permissions.