SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-28564

CRITICAL · CVSS 9.8 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Apache IoTDB versions prior to 2.0.10 are vulnerable to an authentication bypass due to insufficient session expiration, allowing attackers to exploit stale cached credentials for unauthorized access. This critical vulnerability poses a significant risk to systems using affected versions, potentially leading to data breaches or unauthorized control. Organizations utilizing Apache IoTDB should prioritize upgrading to version 2.0.10 to mitigate this risk.

CVE
CVE-2026-28564
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%
Apache

Original NVD Description

Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.