CVE-2026-68570
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information.
This issue affects Apache Doris: from 2.0.0 through 2.1., from 3.0.0 through 3.0., from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4.
Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Doris | 2.0.0 <= 2.1.* | affected |
| Apache Software Foundation | Apache Doris | 3.0.0 <= 3.0.* | affected |
| Apache Software Foundation | Apache Doris | 4.0.0 < 4.0.8 | affected |
| Apache Software Foundation | Apache Doris | 4.1.0 < 4.1.4 | affected |
Weaknesses
- CWE-863: CWE-863: Incorrect Authorization
ADP Enrichment
CVE Program Container
Additional References
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.