Threat Advisory

Apache Doris Flaw Lets Remote Attackers Run Administrative Operations

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting Apache Doris versions The Apache Doris vulnerability affects versions from 2, tracked as CVE-2026-58319 with a CVSS score of 9.1, was discovered in the Frontend HTTP API of Apache Doris, allowing an unauthenticated attacker to run administrative operations and disrupt the cluster due to improper authentication checks on certain administrative REST endpoints; this flaw stems from an improper authentication check on the FE HTTP service, where certain administrative REST endpoints did not verify the caller's identity, potentially causing instability or denial of service, impacting data availability and cluster stability, as Apache Doris is a widely deployed real-time analytics database powering SQL analytics, lakehouse acceleration, and hybrid search for many organizations; the vulnerability affects versions from 2.1.0 up to, but not including, 3.1.0.

RECOMMENDATION:

We recommend you to update Apache Doris to version 3.1.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting Apache Doris versions The Apache Doris vulnerability affects versions from 2, tracked as CVE-2026-58319 with a CVSS score of 9.1, was discovered in the Frontend HTTP API of Apache Doris, allowing an unauthenticated attacker to run administrative operations and disrupt the cluster due to improper authentication checks on certain administrative REST endpoints; this flaw stems from an improper authentication check on the FE HTTP service, where certain administrative REST endpoints did not verify the caller's identity, potentially causing instability or denial of service, impacting data availability and cluster stability, as Apache Doris is a widely deployed real-time analytics database powering SQL analytics, lakehouse acceleration, and hybrid search for many organizations; the vulnerability affects versions from 2.1.0 up to, but not including, 3.1.0.

RECOMMENDATION:

We recommend you to update Apache Doris to version 3.1.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu