CVE-2026-24713 is an Improper Input Validation vulnerability affecting Apache IoTDB versions 1.0.0 before 1.3.7 and 2.0.0 before 2.0.7. Although a CVSS score is unavailable, the vulnerability is described as a JEXL Expression Injection, implying a potential for remote code execution or data manipulation. There is no evidence of active exploitation, nor is public exploit code available, and it is not listed in the KEV catalog. However, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community. Users are advised to upgrade to versions 1.3.7 or 2.0.7 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.3.7CPE matchmatch criteria | cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.0.7CPE matchmatch criteria | cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.