CVE-2026-31377: Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service
CVE-2026-31377 lets unauthenticated attackers reach the Apache Doris Frontend meta service; CVSS score is 7.5.
Apache disclosed CVE-2026-31377, an improper-authentication flaw in the Apache Doris Frontend meta service, rated important. CVSS 3.1 is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), so an unauthenticated remote attacker can access the service with high confidentiality impact. Affected ranges are 2.0.0 before 4.0.8 and 4.1.0 before 4.1.4. Builds before 2.0.0, from 4.0.8 before 4.1.0, and 4.1.4 or later are unaffected. No in-the-wild exploitation is mentioned.
- CVE-2026-31377 is rated important with CVSS 3.1 base 7.5.
- Unauthenticated remote attackers can access the Frontend meta service.
- Vector is network, no privileges, high confidentiality only.
- Fixes are in 4.0.8 and 4.1.4; some ranges are unaffected.
Vulnerabilities mentionedAll →
- CVE-2026-313777.5—Improper Authentication in Apache Doris Frontend Meta Servicepublished · Apache Doris
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-31377 | Improper Authentication in Apache Doris Frontend Meta Service CVE-2026-31377 is an improper authentication vulnerability in the Apache Doris Frontend (FE) meta service. The flaw exists because certain internal metadata endpoints rely on client-supplied headers for authentication without properly verifying the requesting party. An unauthenticated remote attacker can exploit this to bypass access control and access sensitive cluster metadata under specific network configurations. Affected versions include major releases from 2.0.0 through 4.1.4 (excluding 1.2.x and earlier), with fixes available in 4.0.8 and 4.1.4. As of the latest advisory, there is no known public proof-of-concept or active exploitation in the wild. Do: Upgrade Apache Doris to version 4.0.8, 4.1.4, or a later patched release. If an upgrade is not immediately possible, ensure the Frontend meta service endpoints are not exposed to untrusted networks. Monitor for unusual access attempts to internal metadata interfaces. |
Posted by Calvin Kirs on Sep 23 Severity: important CVSS 3.1: 7.5 (high) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected versions: - Apache Doris 2.0.0 before 4.0.8 - Apache Doris 4.1.0 before 4.1.4 - Apache Doris before 2.0.0 unaffected - Apache Doris 4.0.8 before 4.1.0 unaffected - Apache Doris 4.1.4 or later unaffected Description: An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker...
This source does not provide full text. Read it at seclists.org.