CVE-2026-96443: Apache Doris: JDBC driver URL validation bypass leads to remote code execution
Apache Doris JDBC driver URL validation bypass CVE-2026-96443 can lead to remote code execution; Apache rates it moderate.
Apache disclosed CVE-2026-96443, a moderate-severity vulnerability in Apache Doris, in an oss-security post by Calvin Kirs on September 23, 2026. A JDBC driver URL validation bypass can lead to remote code execution. The short notice does not list affected versions or say the flaw is being exploited.
- CVE-2026-96443 is rated moderate in Apache Doris.
- A JDBC driver URL validation bypass can lead to remote code execution.
- The note does not report in-the-wild exploitation or fixed versions.
Vulnerabilities mentionedAll →
- CVE-2026-964436.5—Privileged-User RCE via JDBC Driver URL Bypass in Apache Doris Frontendpublished · Apache Doris
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-96443 | Privileged-User RCE via JDBC Driver URL Bypass in Apache Doris Frontend Apache Doris, an open-source distributed analytical (MPP) database, performs insufficient validation of the JDBC driver URL supplied when configuring external JDBC connections (CWE-829, inclusion of functionality from an untrusted control sphere). An attacker who already holds privileged, admin-level access to a Doris cluster can submit a crafted JDBC driver URL that causes arbitrary code to execute on the Frontend (FE) node. Successful abuse gives code execution as the Doris service account on the FE host, exposing cluster metadata, stored credentials, and the underlying server. Any organization running Apache Doris with JDBC catalog/resource functionality is potentially affected, but exploitation requires privileged access first (e.g., stolen or misused admin credentials), which limits opportunistic external attacks. The CVE has no CVSS score yet, is not in CISA's KEV catalog, and no public proof-of-concept or in-the-wild exploitation is known. |
Posted by Calvin Kirs on Sep 23 Severity: moderate https://doris.apache.org https://www.cve.org/CVERecord?id=CVE-2026-96443
This source does not provide full text. Read it at seclists.org.