https://seclists.org/oss-sec/2026/q3/69: CVE-2026-24014: Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write
Published Jul 6, 2026
·Updated
Affected Software
1 affected component
Apache IoTDB>1.3.3<=2.0.8
Frequently Asked Questions
1
What is the severity of CVE-2026-24014?
CVE-2026-24014 is classified as an important severity vulnerability.
2
Which versions of Apache IoTDB are affected by CVE-2026-24014?
Apache IoTDB versions 1.3.3 before 2.0.8 are affected by CVE-2026-24014.
3
What does CVE-2026-24014 exploit in Apache IoTDB?
CVE-2026-24014 exploits a path traversal vulnerability in the DataNode's internal RPC interface.
4
How can I fix CVE-2026-24014?
To fix CVE-2026-24014, upgrade Apache IoTDB to version 2.0.8 or later.
5
What could be the potential impact of CVE-2026-24014?
The potential impact of CVE-2026-24014 includes arbitrary file write capabilities if the internal DataNode RPC port is exposed.