Apache Doris

4 known vulnerabilities in Apache Doris, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-96443 CVSS 6.5 medium Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.
  • CVE-2026-31377 CVSS 7.5 high An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to…
  • CVE-2026-72524 CVSS 8.8 high Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data…
  • CVE-2026-68570 CVSS 6.5 medium Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not…