{"schema_version": "1.6.1", "id": "CVE-2026-40009", "summary": "Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor", "details": "Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB.\nAuthenticated users can escalate to full tree-path access by renaming\nthemselves to __internal_auditor.\n\n\nThis issue affects Apache IoTDB: from 2.0.8 before 2.0.10.\n\nUsers are recommended to upgrade to version 2.0.10, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "2.0.8"}, {"fixed": "2.0.10"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/65hh7dh28rcxlzdzwdpt630321tr8b61"}]}