Vulnerability Bulletins |
CVE-2026-40005 |
|
| Affected software | APACHE |
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue. |
|
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-40005 | |






