๐Ÿ” CVE Alert

CVE-2026-31377

HIGH 7.5

Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service

CVSS Score
7.5
EPSS Score
0.6%
EPSS Percentile
50th

An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information. This issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Versions 1.2.x and earlier are not affected by this header-trust vulnerability. Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.

CWE CWE-287
Vendor apache software foundation
Product apache doris
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache doris

Be the first to know when new high vulnerabilities affecting apache software foundation apache doris are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Apache Software Foundation / Apache Doris
2.0.0 < 4.0.8 4.1.0 < 4.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/rf4ocqmzxvnwnxpsooj2lkzjl68b1m9q

Credits

๐Ÿ” Mapta / BugBunny_ai ๐Ÿ” Calvin Kirs, Security Researcher at SelectDB ๐Ÿ” Vlary (Huntree Security Team) ๐Ÿ” Vladimir Tokarev (g1nd1l4) ๐Ÿ” lalalala5678 ๐Ÿ” 4ra2n (A code security AI agent) ๐Ÿ” Fakile Emmanuel ๐Ÿ” Fried Chicken