<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – InfluxDB (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/influxdb.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/influxdb-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – InfluxDB (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:00 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-25751 – FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An inf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25751</guid>
    <pubDate>Fri, 06 Feb 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25751</strong></p>
  <p>FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an unauthenticated, remote attacker to obtain the full system configuration, including administrative credentials for the InfluxDB database. Possession of…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-30896 – InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30896</guid>
    <pubDate>Thu, 21 Nov 2024 11:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-30896</strong></p>
  <p>InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36640 – influxData influxDB before v1.8.10 contains no authentication mechanism or contr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36640</guid>
    <pubDate>Fri, 02 Sep 2022 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36640</strong></p>
  <p>influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to an…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-20933 – InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20933</guid>
    <pubDate>Thu, 19 Nov 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-20933</strong></p>
  <p>InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10329 – Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10329</guid>
    <pubDate>Fri, 31 May 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10329</strong></p>
  <p>Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10329">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
