https://seclists.org/oss-sec/2026/q3/117: CVE-2026-40452: Apache IoTDB: Authorization bypass in /st/v2/fastLastQuery exposes last-value data to unauthorized authenticated users
Published Jul 10, 2026
·Updated
Affected Software
2 affected components
Apache IoTDB>1.3.5<1.3.8
Apache IoTDB>2.0.5<2.0.10
Frequently Asked Questions
1
What is the severity of CVE-2026-40452?
The severity of CVE-2026-40452 is classified as moderate.
2
Which versions of Apache IoTDB are affected by CVE-2026-40452?
Apache IoTDB versions 1.3.5 before 1.3.8 and 2.0.5 before 2.0.10 are affected by CVE-2026-40452.
3
What type of vulnerability is CVE-2026-40452?
CVE-2026-40452 is an Incorrect Authorization, Improper Access Control vulnerability.
4
How do I fix CVE-2026-40452?
To fix CVE-2026-40452, upgrade Apache IoTDB to version 1.3.8 or higher, or 2.0.10 or higher.
5
What does CVE-2026-40452 expose to unauthorized users?
CVE-2026-40452 exposes last-value data to unauthorized authenticated users through the /rest/v2/fastLastQuery endpoint.