CVE-2026-24713
CRITICALApache IoTDB 1.0.0-1.3.6/2.0.0-2.0.6 - Input Validation
Title source: llmDescription
Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.
Scores
CVSS v3
9.8
EPSS
0.0005
EPSS Percentile
14.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-20
CWE-917
Status
published
Products (2)
apache/iotdb
1.0.0 - 1.3.7
org.apache.iotdb/iotdb-core
1.0.0 - 1.3.7Maven
Published
Mar 09, 2026
Tracked Since
Mar 09, 2026