Impact
The vulnerability originates from improper privilege management and authorization controls that allow an authenticated user to rename themselves to the privileged role __internal_auditor, thereby gaining full access to all tree‑path data. This is a classic privilege escalation flaw reflected in the CWE-269 and CWE-284 weaknesses and can compromise confidentiality, integrity, and availability—for instance, the attacker can read, modify, or delete any data stored in the database.
Affected Systems
The flaw affects Apache IoTDB releases from version 2.0.8 through the last patch before 2.0.10. All deployments of Apache IoTDB that have not applied the 2.0.10 update are potentially vulnerable. Apache IoTDB is a time‑series database product maintained by the Apache Software Foundation, widely used for Internet‑of‑Things applications.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests that exploitation is considered unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires additional privileges; an attacker can rename themselves to __internal_auditor to bypass normal access controls. The description indicates that the failure occurs when a logged‑in user alters their account name to a privileged one within the system.
OpenCVE Enrichment