CVE-2026-28564

Unzureichende Sitzungsablaufzeit und Authentifizierungsumgehung durch Aufzeichnungs-Wiedergabe-Schwachstelle in Apache IoTDB.

criticalEPSS 0.7%

Description

Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.

Metrics

9.8
Source: nvd-v3
51.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.7 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-10 07:08 UTC
CWE-613, CWE-294

Weakness classes (CWE)

  • CWE-613Base

    Insufficient Session Expiration

    According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

    cwe.mitre.org →
  • CWE-294Base

    Authentication Bypass by Capture-replay

    A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

    cwe.mitre.org →

References & sources

Linked advisories