https://seclists.org/oss-sec/2026/q3/68: CVE-2026-24013: Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC
Published Jul 6, 2026
·Updated
Affected Software
1 affected component
Apache IoTDB>1.3.3<=2.0.8
Frequently Asked Questions
1
What is the severity of CVE-2026-24013?
The severity of CVE-2026-24013 is classified as moderate.
2
How do I fix CVE-2026-24013?
To fix CVE-2026-24013, upgrade Apache IoTDB to version 2.0.8 or later.
3
What is the cause of CVE-2026-24013?
CVE-2026-24013 is caused by a lack of strict validation of the sessionId parameter in certain Thrift RPC query handlers.
4
Which versions of Apache IoTDB are affected by CVE-2026-24013?
Apache IoTDB versions 1.3.3 before 2.0.8 are affected by CVE-2026-24013.
5
Can CVE-2026-24013 lead to unauthorized access?
Yes, CVE-2026-24013 enables authentication bypass, allowing attackers to gain unauthorized access.