CRITICAL9.1
PYSEC-2026-2080
Quick fix
PYSEC-2026-2080 — apache-iotdb: upgrade to the fixed version with the command below.
pip install --upgrade 'apache-iotdb>=2.0.8'Details
Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, receive valid query results. This allows authentication bypass and unauthorized reading of time-series data.
This issue affects Apache IoTDB: from 1.3.3 before 2.0.8.
Users are recommended to upgrade to version 2.0.8, which fixes the issue.
Are you affected?
Enter the version of the package you're using.