CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-36640

Critical · CVSS 9.8

influxData influxDB — Missing authentication / unauthenticated remote command execution (CWE-276 incorrect default permissions)

CVSS
9.8
nvd
EPSS
2.05%
79th pct
KEV
No
Class
oss containerizable
CWE-276

Description

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization."

Search profile — drives PoC discovery

Symbols influxdbauthenticationauthorizationHTTP API/query/writeInfluxQLINFLUXDB_HTTP_AUTH_ENABLEDauth-enabled
Keywords CVE-2022-36640influxdb unauthenticated RCEinfluxdb no authenticationinfluxdb default credentials bypassinfluxdb missing auth exploitinfluxdb 1.8 authentication bypassBitnami influxdb CVE-2022-36640influxdb arbitrary command executioninfluxdb CWE-276 PoC
Versions: < 1.8.10

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Bitnami influxdb 0 → 1.8.0

References

Status: enriched · ingested 2026-07-05T18:00:39.000Z · profiled 2026-07-05T18:30:39.000Z