Security Advisory
CVE-2026-40009
6.5
MEDIUM
Vulnerability Description
Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB.
Authenticated users can escalate to full tree-path access by renaming
themselves to __internal_auditor.
This issue affects Apache IoTDB: from 2.0.8 before 2.0.10.
Users are recommended to upgrade to version 2.0.10, which fixes the issue.
Published Date
July 10, 2026
Official Source
NIST NVD Advisory