{
  "from_raw": "Haonan Hou <haonan@apache.org>",
  "from": "Haonan Hou <ha...@apache.org>",
  "gravatar": "077d6b3571cf3c6b81dadb75bcf8f139",
  "to": "an...@apache.org,\n de...@iotdb.apache.org",
  "subject": "CVE-2026-24013: Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC",
  "message-id": "<e42ee5ff-8e02-c27c-7e1b-85dca6dfc249@apache.org>",
  "mid": "6pwkgnqhbm56mvn309f87snm84s0b75y",
  "permalinks": [
    "6pwkgnqhbm56mvn309f87snm84s0b75y",
    "r928ba03cc4cd04dd469cbcce0e8cc9e73fef2bb01003e7739dcadacf@<announce.apache.org>"
  ],
  "dbid": "2c34910605973f9fd2efb94bd539ff04887d0a8eeffb8056533e26b02a28aae1",
  "cc": "de...@iotdb.apache.org",
  "epoch": 1783321651,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/07/06 07:07:31",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache IoTDB 1.3.3 before 2.0.8\n\nDescription:\n\nAuthentication Bypass by Spoofing vulnerability in Apache IoTDB.\nCertain Thrift RPC query handlers lack strict validation of the sessionId\nparameter. An attacker can construct requests with a forged sessionId and,\nwithout performing openSession authentication, receive valid query results.\nThis allows authentication bypass and unauthorized reading of time-series\ndata.\n\n\nThis issue affects Apache IoTDB: from 1.3.3 before 2.0.8.\n\nUsers are recommended to upgrade to version 2.0.8, which fixes the issue.\n\nCredit:\n\nYan Nan (Detecon Security Lab) (finder)\n\nReferences:\n\nhttps://iotdb.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-24013\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache IoTDB 1.3.3 before 2.0.8\n\nDescription:\n\nAuthentication Bypass by Spoofing vulnerability in Apache IoTDB.\nCertain Thrift RPC query handlers lack strict ",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2653,
  "id": "6pwkgnqhbm56mvn309f87snm84s0b75y"
}