CVE-2026-40452
Apache Software Foundation Apache IoTDB
Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. This issue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.
- CVSS
- 7.5
- EPSS
- 0.29% 20.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.10