CVE-2026-96443
Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.
- Published Sep 23, 2026
- CVSS 6.5 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.