Junglewise Threat Intelligence

CVE-2026-68570: Apache Doris authorization bypass in privilege checks

CVE-2026-68570 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Vendors: Apache.

Executive brief

Apache Doris is an open-source data warehouse and analytics platform. This vulnerability allows authenticated users to bypass privilege controls and access data they should not be able to read, exposing sensitive business information. An attacker with valid credentials can view confidential or restricted datasets without proper authorization.

Technical details

An incorrect authorization vulnerability in Apache Doris fails to properly enforce privilege checks on data access operations. An authenticated user can craft requests that bypass the access control mechanism to read data outside their assigned permissions. The vulnerability affects multiple version branches (2.0–2.1, 3.0, 4.0 before 4.0.8, and 4.1 before 4.1.4). Fix versions 4.0.8 and 4.1.4 address the authorization logic to restore proper privilege enforcement. No evidence of active exploitation in the wild has been reported.

Affected products

  • Apache Doris 2.0.0 through 2.1.x, 3.0.0 through 3.0.x, 4.0.0 before 4.0.8, 4.1.0 before 4.1.4

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixes available in 4.0.8 and 4.1.4

References