Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the issue.
The vulnerability classified as CWE-94 (code injection) allows an attacker to inject and execute arbitrary code on a vulnerable Apache IoTDB server. The attack can be conducted remotely over the network without requiring an account or any user interaction. The detailed exploitation mechanism was not disclosed in the vendor's description.
Successful exploitation of the vulnerability gives the attacker full control over the system — data breach is possible, modification of the time series database, and potentially further lateral movement in the infrastructure.
Apache IoTDB should be updated to version 1.3.0 or newer as soon as possible, which eliminates the described vulnerability. The vendor explicitly recommends this version as a solution to the problem.
Apache IoTDB in versions 1.0.0 to 1.2.2 inclusive.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Iotdb
APPApache1.0.0 – 1.3.0 (excl.)
Related vulnerabilities
Apache IoTDB — pominięcie uwierzytelnienia przez sfałszowany sessionId (Thrift RPC)
Apache IoTDB: path traversal umożliwiający zapis dowolnych plików
Krytyczna podatność w Apache IoTDB (CVE-2026-24015)
Nieprawidłowa walidacja danych wejściowych w Apache IoTDB — RCE/injection
Apache IoTDB: RCE przez rejestrację złośliwej funkcji UDF z niezaufanego URI