Improper Authentication in Apache Doris - CVE-2026-31377
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive cluster information.
The vulnerability exists due to improper authentication in the Apache Doris Frontend (FE) meta service when handling requests to internal metadata service endpoints. A remote attacker can supply node information that bypasses the intended access control to disclose sensitive cluster information.
Exploitation is possible under certain network configurations.