HIGH
TDengine: UDF lead to RCE
Published Jul 15, 2026
7.2
HIGHCVSS 3.1
EPSS 0.54%
Description
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a crafted shared library and install it as a user-defined function, such as eval, then execute arbitrary C code on the TDengine server side through database queries. This issue is fixed in version 3.4.1.15.
Affected products
-
- Version < 3.4.1.15StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44766 Advisory
- https://github.com/taosdata/TDengine/security/advisories/GHSA-f7wh-p233-87xv exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44766 | Advisory | |
| https://github.com/taosdata/TDengine/security/advisories/GHSA-f7wh-p233-87xv | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 15, 2026
Updated Jul 18, 2026
Reserved Jul 13, 2026
Link CVE-2026-62350
CISA Vulnrichment
Updated Jul 18, 2026
ENISA EUVD
EUVD-2026-44766 Assigner GitHub_M
Published Jul 15, 2026
Updated Jul 18, 2026
Exploited since n/a
Link EUVD-2026-44766