PT-2026-24048 · Apache · Apache Iotdb

Yongzhi Liu

·

Published

2026-03-09

·

Updated

2026-03-09

·

CVE-2026-24713

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache IoTDB versions 1.0.0 through 1.3.6 Apache IoTDB versions 2.0.0 through 2.0.6
Description An improper input validation issue exists in Apache IoTDB. The issue impacts the software’s ability to correctly handle user-supplied data, potentially leading to unexpected behavior or security compromises.
Recommendations Upgrade to version 1.3.7. Upgrade to version 2.0.7.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-24713
GHSA-6W48-2G9J-V9Q5

Affected Products

Apache Iotdb