Apache Doris disclosures: improper authentication in FE meta service (CVE-2026-31377) and JDBC driver URL validation bypass RCE (CVE-2026-96443)
Two Apache Doris vulnerabilities were disclosed on oss-security on 2026-09-23: an improper-authentication flaw in the Frontend meta service rated important (CVSS 7.5) and a moderate-severity JDBC driver URL validation bypass that can lead to remote code…
Two security advisories for Apache Doris were posted to oss-security on 2026-09-23. CVE-2026-31377 is an improper authentication vulnerability in the Apache Doris Frontend (FE) meta service, rated important, with a CVSS 3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). An unauthenticated remote attacker can access the meta service with high confidentiality impact only. Affected versions are 2.0.0 before 4.0.8 and 4.1.0 before 4.1.4; versions before 2.0.0, from 4.0.8 up to (but excluding) 4.1.0, and 4.1.4 or later are unaffected. Fixes are available in 4.0.8 and 4.1.4. The second disclosure, CVE-2026-96443, announced by Calvin Kirs, is a JDBC driver URL validation bypass in Apache Doris that can lead to remote code execution and is rated moderate severity by Apache. The notice for CVE-2026-96443 does not list affected or fixed versions. Neither report mentions in-the-wild exploitation of either vulnerability.
- CVE-2026-31377: improper authentication in Apache Doris FE meta service, disclosed on oss-security 2026-09-23.
- CVE-2026-31377 rated important with CVSS 3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) — network-exploitable, no privileges or user interaction required, high confidentiality impact only.
- CVE-2026-31377 affected versions: 2.0.0 before 4.0.8 and 4.1.0 before 4.1.4; fixed in 4.0.8 and 4.1.4. Versions before 2.0.0, 4.0.8 (inclusive) before 4.1.0, and 4.1.4 or later are unaffected.
- CVE-2026-96443: JDBC driver URL validation bypass in Apache Doris leading to remote code execution, disclosed by Calvin Kirs on oss-security 2026-09-23, rated moderate severity.
- No affected or fixed versions were specified for CVE-2026-96443 in the report.
- Neither report indicates in-the-wild exploitation.
Coverage timelineoldest first · each row is one article
- · 3d agoCVE-2026-31377: Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service
oss-security· 56
CVE-2026-31377 lets unauthenticated attackers reach the Apache Doris Frontend meta service; CVSS score is 7.5.
- · 3d agoCVE-2026-96443: Apache Doris: JDBC driver URL validation bypass leads to remote code execution
oss-security· 40
Apache Doris JDBC driver URL validation bypass CVE-2026-96443 can lead to remote code execution; Apache rates it moderate.
Vulnerabilities in this storyAll →
- CVE-2026-313777.5—Improper Authentication in Apache Doris Frontend Meta Servicepublished · Apache Doris
- CVE-2026-964436.5—Privileged-User RCE via JDBC Driver URL Bypass in Apache Doris Frontendpublished · Apache Doris
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure |
|---|