Description
An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints.



The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information.



This issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Versions 1.2.x and earlier are not affected by this header-trust vulnerability.




Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
Published: 2026-09-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Internal Metadata
Action: Immediate Patch
AI Analysis

Impact

An authentication bypass in the Apache Doris Frontend meta service allows an unauthenticated attacker to reach internal metadata endpoints, exposing cluster information. The flaw arises from reliance on client‑supplied node data without proper verification, corresponding to CWE‑287. The impact involves potential disclosure of sensitive configuration and state data, as the attacker can query services intended for trusted nodes only.

Affected Systems

Apache Doris versions 2.0.0 through 2.0.*, 2.1.0 through 2.1.*, 3.0.0 through 3.0.*, 3.1.0 through 3.1.*, and 4.0.0 before 4.0.8 as well as 4.1.0 before 4.1.4 are vulnerable; earlier 1.2.x releases are not affected.

Risk and Exploitability

The CVSS base score of 7.5 indicates high severity of an unauthorized token or credential bypass. The EPSS score of <1% indicates a very low probability of exploitation. The lack of a publicly listed KEV entry suggests no confirmed exploitation yet, but the vulnerability can be exercised by any remote party with network reach to the FE metadata interfaces under certain configurations. The condition requires that the endpoint accepts client‑supplied node information, but the specific protocol is not stated. Based on the description, it is inferred that remote network access to the FE meta service endpoints could enable the exploitation, although the exact attack vector is not explicitly defined.

Generated by OpenCVE AI on September 23, 2026 at 14:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Doris to at least version 4.0.8 or 4.1.4, which contain the fix for the authentication bypass.
  • If upgrading immediately is not feasible, restrict network access to the FE meta service endpoints using firewalls or network segmentation so that only trusted infrastructure can reach them.
  • Configure the cluster to reject or validate client‑supplied node data for authentication, ensuring the meta service checks proper credentials before granting access.

Generated by OpenCVE AI on September 23, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information. This issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Versions 1.2.x and earlier are not affected by this header-trust vulnerability. Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
Title Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-23T14:06:44.071Z

Reserved: 2026-03-09T05:56:59.960Z

Link: CVE-2026-31377

cve-icon Vulnrichment

Updated: 2026-09-23T14:06:38.140Z

cve-icon NVD

Status : Received

Published: 2026-09-23T09:17:08.380

Modified: 2026-09-23T15:17:13.907

Link: CVE-2026-31377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:45:05Z

Weaknesses