https://seclists.org/oss-sec/2026/q3/111: CVE-2026-28564: Apache IoTDB: ST Basic Authentication Accepts Stale Cached Cdentials
Published Jul 10, 2026
·Updated
Affected Software
1 affected component
Apache IoTDB>1.0.0<2.0.10
Frequently Asked Questions
1
What is the severity of CVE-2026-28564?
The severity of CVE-2026-28564 is classified as important.
2
Which versions of Apache IoTDB are affected by CVE-2026-28564?
CVE-2026-28564 affects Apache IoTDB version 1.0.0 before 2.0.10.
3
What type of vulnerability is CVE-2026-28564?
CVE-2026-28564 is an insufficient session expiration and authentication bypass vulnerability.
4
How can I fix CVE-2026-28564?
To fix CVE-2026-28564, upgrade Apache IoTDB to version 2.0.10 or later.
5
What issue does CVE-2026-28564 cause in Apache IoTDB?
CVE-2026-28564 causes the REST Basic Authentication to accept stale cached credentials.