CVE-2026-40009: Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor
Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by renaming themselves to internalauditor.
This issue affects Apache IoTDB: from 2.0.8 before 2.0.10.
Users are recommended to upgrade to version 2.0.10, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache IoTDBto a version that resolves this vulnerability.Fixed in 2.0.10Patch CVE-2026-40009
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40009?
CVE-2026-40009 has a medium severity level with a CVSS score of 6.5.
How do I fix CVE-2026-40009?
To remediate CVE-2026-40009, users should upgrade to Apache IoTDB version 2.0.10 or later.
What type of vulnerability is CVE-2026-40009?
CVE-2026-40009 is classified as an Improper Privilege Management and Improper Access Control vulnerability.
Who is affected by CVE-2026-40009?
The vulnerability affects authenticated users of Apache IoTDB versions from 2.0.8 to earlier than 2.0.10.
What can an attacker do with CVE-2026-40009?
An attacker can escalate their privileges to gain full tree-path access by renaming themselves to __internal_auditor.