{"id":"CVE-2026-24013","aliases":["PYSEC-2026-2080"],"title":"Authentication Bypass by Spoofing vulnerability in Apache IoTDB.","summary":"Authentication Bypass by Spoofing vulnerability in Apache IoTDB.\nCertain Thrift RPC query handlers lack strict validation of the sessionId\nparameter. An attacker can construct requests with a forged sessionId and,\nwithout performing open…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","vendor":"apache-iotdb","product":"apache-iotdb","ecosystem":"pip","affected":["apache-iotdb >= 1.3.3, < 2.0.8"],"patched":["apache-iotdb 2.0.8"],"published":"2026-07-06","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/PYSEC-2026-2080","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/07/06/11"},{"url":"https://lists.apache.org/thread/6pwkgnqhbm56mvn309f87snm84s0b75y"}],"tags":["osv","pip"],"epss":0.00635,"epssPercentile":0.49058,"ingestedAt":"2026-07-09T18:56:35.384Z","slug":"CVE-2026-24013","body":"## Overview\n\nAuthentication Bypass by Spoofing vulnerability in Apache IoTDB.\nCertain Thrift RPC query handlers lack strict validation of the sessionId\nparameter. An attacker can construct requests with a forged sessionId and,\nwithout performing openSession authentication, receive valid query results.\nThis allows authentication bypass and unauthorized reading of time-series\ndata.\n\n\nThis issue affects Apache IoTDB: from 1.3.3 before 2.0.8.\n\nUsers are recommended to upgrade to version 2.0.8, which fixes the issue.\n\n## Affected packages\n\n- `apache-iotdb >= 1.3.3, < 2.0.8`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `apache-iotdb 2.0.8`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}