Impact
TDengine is an open‑source time‑series database used for IoT workloads. In versions earlier than 3.4.1.15, a data‑reader role identified as admin_user could run the CREATE UDF command even though standard users should have read‑only access to non‑database objects. This flaw allows an attacker with standard user credentials to deploy arbitrary user‑defined functions, potentially giving them a foothold for further exploitation within the database environment.
Affected Systems
The vulnerability affects TDengine deployments from taosdata, specifically any TDengine Cloud DB instance running a version earlier than 3.4.1.15. Updating to 3.4.1.15 or newer resolves the issue.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. An attacker would need database access with a standard user that has inadvertently elevated privileges, and could exploit the flaw locally within the managed database service. The primary risk is the ability to inject malicious UDF code beyond the intended read‑only boundary.
OpenCVE Enrichment