Sploitus

CVE-2025-26864

No indexed exploits for CVE-2025-26864 yet

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.

Affected products
Apache Iotdb
Apache Iotdb
< 1.3.4, 2.0.1
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
0.7% (50th percentile)
Weakness
CWE-532, CWE-200
NVD status
Analyzed
Published
2025-05-14
CVE-2025-26864 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-26864 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-26864 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.