https://seclists.org/oss-sec/2026/q1/286: CVE-2026-24015: Apache IoTDB: InsecuDefault Configuration Vulnerability
Published Mar 9, 2026
·Updated
Affected Software
2 affected components
Apache IoTDB<1.3.7
Apache IoTDB<2.0.7
Frequently Asked Questions
1
What is the severity of CVE-2026-24015?
The severity of CVE-2026-24015 is classified as important.
2
Which versions of Apache IoTDB are affected by CVE-2026-24015?
Apache IoTDB versions 1.0.0 before 1.3.7 and 2.0.0 before 2.0.7 are affected by CVE-2026-24015.
3
How do I fix CVE-2026-24015?
To fix CVE-2026-24015, users should upgrade to Apache IoTDB version 1.3.7 or 2.0.7.
4
What is the default configuration vulnerability in CVE-2026-24015?
CVE-2026-24015 is an insecuDefault configuration vulnerability in Apache IoTDB, which can expose users to security risks.
5
When was CVE-2026-24015 published?
CVE-2026-24015 was published on March 9, 2026.