Incorrect authorization in Apache Doris - CVE-2026-68570
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in Apache Doris authorization checks when performing operations subject to privilege checks. A remote user can bypass privilege checks and access data they are not authorized to read to disclose sensitive information.