Impact
The vulnerability is an incorrect authorization check that lets an authenticated user bypass privilege verification and perform any DML or DDL operation on tables in Apache Doris. This permits reading, writing, or dropping arbitrary tables, compromising data confidentiality, integrity, and availability. The weakness corresponds to CWE-863.
Affected Systems
Affected software is Apache Doris developed by the Apache Software Foundation. Versions 3.1.0 through 3.1.*, 4.0.0 through 4.0.7, and 4.1.0 through 4.1.3 are vulnerable.
Risk and Exploitability
The flaw can be exploited by any authenticated user; no additional privileges are needed, making it possible for low‑privilege accounts to gain full control over database objects. No EPSS score is available, and the vulnerability is not listed in CISA's KEV catalog, but the lack of CVSS data and the high impact of privilege escalation suggest a high risk. Attackers would need authenticated access, likely through the application or client connections, to issue privileged queries and bypass checks.
OpenCVE Enrichment