Description
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information.



This issue affects Apache Doris: from 2.0.0 through 2.1.*, from 3.0.0 through 3.0.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4.



Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Disclosure
Action: Immediate Patch
AI Analysis

Impact

An authentication misconfiguration in Apache Doris allows a user who is already authenticated to bypass the system’s privilege checks and read data that the user should not be able to access. This privilege escalation results in the accidental disclosure of sensitive information. The weakness is classified as a permissions and access control failure (CWE‑863).

Affected Systems

The vulnerability affects all versions of Apache Doris from 2.0.0 up to 2.1.*, from 3.0.0 up to 3.0.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3. The vendor is the Apache Software Foundation and the product is Apache Doris.

Risk and Exploitability

With a CVSS score of 6.5, the vulnerability can be leveraged by any authenticated user and therefore does not require an additional foothold in the network. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, but the ability to extract sensitive data without authorization makes it a serious business threat. In practice an attacker would need only a valid user session to trigger the bypass and view restricted data; however, the low EPSS score indicates that real-world exploitation is considered unlikely.

Generated by OpenCVE AI on September 21, 2026 at 01:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Doris to a fixed release – at least version 4.0.8 or 4.1.4, which eliminates the authorization bypass.
  • If an upgrade is not immediately possible, enforce strict least‑privilege policies at the client or application level to limit what authenticated users can query, and isolate sensitive data sets behind additional access controls.
  • Continuously monitor access logs for abnormal query patterns or repeated unauthorized access attempts, and apply any vendor patches as soon as they become available.

Generated by OpenCVE AI on September 21, 2026 at 01:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache doris
Vendors & Products Apache
Apache doris

Mon, 14 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This issue affects Apache Doris: from 2.0.0 through 2.1.*, from 3.0.0 through 3.0.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
Title Apache Doris: Authorization bypass leading to unauthorized data access
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:38:35.447Z

Reserved: 2026-07-31T08:14:22.640Z

Link: CVE-2026-68570

cve-icon Vulnrichment

Updated: 2026-09-14T16:08:04.715Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T10:17:00.690

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-68570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:45:07Z

Weaknesses