A high-severity vulnerability was found in TDengine, a time-series database optimized for Internet of Things devices. The issue allows a user with create udf privilege to upload a crafted shared library and install it as a user-defined function, enabling execution of arbitrary C code on the TDengine server side through database queries. This issue is fixed in version 3.4.1.15. The vulnerability could allo [truncated]
CVE-2026-62348 is a medium-severity vulnerability in TDengine Enterprise, allowing an authenticated low-privilege SQL user to run KILL SSMIGRATE <id> against an active shared-storage migration. This issue is fixed in version 3.4.1.15. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM. The CVE record was published on 2026-07-15T19:18:37.107Z and has not been modified since then.
CVE-2026-42542 is a HIGH severity vulnerability in TDengine, an open source time-series database optimized for Internet of Things devices. Versions 3.4.0.0 through 3.4.1.5 are vulnerable. An unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. The issue is fixed in version 3.4.1.6.