CVE-2026-96443: Apache Doris: JDBC driver URL validation bypass leads to remote code execution
Apache Doris JDBC driver URL validation bypass CVE-2026-96443 can lead to remote code execution; Apache rates it moderate.
Apache disclosed CVE-2026-96443, a moderate-severity vulnerability in Apache Doris, in an oss-security post by Calvin Kirs on September 23, 2026. A JDBC driver URL validation bypass can lead to remote code execution. The short notice does not list affected versions or say the flaw is being exploited.