{
  "from_raw": "Haonan Hou <haonan@apache.org>",
  "from": "Haonan Hou <ha...@apache.org>",
  "gravatar": "077d6b3571cf3c6b81dadb75bcf8f139",
  "to": "an...@apache.org,\n de...@iotdb.apache.org",
  "subject": "CVE-2026-40452: Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users",
  "message-id": "<e0d4ed1a-b402-6cef-fe33-ba533933a932@apache.org>",
  "mid": "04j2l6dosyboor4o2gvrzbrcrpllmh95",
  "permalinks": [
    "04j2l6dosyboor4o2gvrzbrcrpllmh95",
    "r13408376ce59a0f5be22703809075137354739dd63f1fa7b81ebb9a8@<announce.apache.org>"
  ],
  "dbid": "33bbe957ae314e9e931d66c26eeb1f48fa7ecf9524a8fbd2cec77f9a49a437df",
  "cc": "de...@iotdb.apache.org",
  "epoch": 1783665287,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/07/10 06:34:47",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache IoTDB 1.3.5 before 1.3.8\n- Apache IoTDB 2.0.5 before 2.0.10\n\nDescription:\n\nIncorrect Authorization, Improper Access Control vulnerability in Apache IoTDB.\nAuthorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users.\n\n\nThis issue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10.\n\nUsers are recommended to upgrade to version 2.0.10, which fixes the issue.\n\nCredit:\n\nbugbunny.ai (finder)\n\nReferences:\n\nhttps://iotdb.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-40452\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache IoTDB 1.3.5 before 1.3.8\n- Apache IoTDB 2.0.5 before 2.0.10\n\nDescription:\n\nIncorrect Authorization, Improper Access Control vulnerability in Apache IoT",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2589,
  "id": "04j2l6dosyboor4o2gvrzbrcrpllmh95"
}