Input validation error in Apache Doris - CVE-2026-96443
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local privileged user to execute arbitrary code on the frontend.
The vulnerability exists due to insufficient validation in the JDBC driver URL handling functionality when processing a JDBC driver URL. A local privileged user can provide a malicious JDBC driver URL to execute arbitrary code on the frontend.