Improper Authentication in Apache Doris - CVE-2026-31377

 

Improper Authentication in Apache Doris - CVE-2026-31377

Published: September 24, 2026


Vulnerability identifier: #VU151962
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31377
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive cluster information.

The vulnerability exists due to improper authentication in the Apache Doris Frontend (FE) meta service when handling requests to internal metadata service endpoints. A remote attacker can supply node information that bypasses the intended access control to disclose sensitive cluster information.

Exploitation is possible under certain network configurations.


Affected software

Apache Doris

How to mitigate CVE-2026-31377

Install security update from vendor's website.

Apache Doris - update to 1.2.1 rc01

External References

Related Security Bulletins