SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-40005

CRITICAL · CVSS 9.1 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Apache IoTDB versions prior to 2.0.10 are vulnerable to a path traversal flaw that allows attackers to write arbitrary files within any directory where the IoTDB process has write permissions. This critical vulnerability poses a significant risk of unauthorized file manipulation, potentially leading to further exploitation or data compromise. Organizations using affected versions should prioritize upgrading to 2.0.10 to mitigate this risk.

CVE
CVE-2026-40005
Severity
CRITICAL
CVSS
9.1
EPSS
0.41%
Apache

Original NVD Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.