CVE-2026-72524 PUBLISHED

Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables

Assigner: apache
Reserved: 10.08.2026 Published: 14.09.2026 Updated: 14.09.2026

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to.

This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3.

Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Doris
Versions Default: unaffected
  • affected from 3.1.0 to 3.1.* (incl.)
  • affected from 4.0.0 to 4.0.7 (incl.)
  • affected from 4.1.0 to 4.1.3 (incl.)

Credits

  • Calvin Kirs, Security Researcher at SelectDB finder

References

Problem Types

  • CWE-863: Incorrect Authorization CWE