CVE-2026-68570 PUBLISHED

Apache Doris: Authorization bypass leading to unauthorized data access

Assigner: apache
Reserved: 31.07.2026 Published: 14.09.2026 Updated: 14.09.2026

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information.

This issue affects Apache Doris: from 2.0.0 through 2.1., from 3.0.0 through 3.0., from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4.

Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Doris
Versions Default: unaffected
  • affected from 2.0.0 to 2.1.* (incl.)
  • affected from 3.0.0 to 3.0.* (incl.)
  • affected from 4.0.0 to 4.0.8 (excl.)
  • affected from 4.1.0 to 4.1.4 (excl.)

Credits

  • Calvin Kirs, Security Researcher at SelectDB finder

References

Problem Types

  • CWE-863: Incorrect Authorization CWE