Executive brief
Apache Doris is a cloud-native data warehouse system used for analytics and reporting. An authentication bypass vulnerability in the Frontend metadata service allows remote attackers without credentials to access sensitive cluster information, potentially exposing database schemas, node configurations, and internal system details.
Technical details
An improper authentication vulnerability in Apache Doris Frontend (FE) meta service endpoints trusts client-supplied node information for authentication without sufficient verification. This allows unauthenticated remote attackers over the network to bypass access controls and access internal metadata interfaces. Under certain network configurations, attackers can retrieve sensitive cluster information.
Affected products
- Apache Doris 2.0.0 through 2.1.*, 3.0.0 through 3.1.*, 4.0.0 before 4.0.8, 4.1.0 before 4.1.4
Timeline
- 2026-09-23: disclosed