Executive brief
Apache Doris is an open-source data warehouse and analytics platform. This vulnerability allows authenticated users to bypass privilege controls and access data they should not be able to read, exposing sensitive business information. An attacker with valid credentials can view confidential or restricted datasets without proper authorization.
Technical details
An incorrect authorization vulnerability in Apache Doris fails to properly enforce privilege checks on data access operations. An authenticated user can craft requests that bypass the access control mechanism to read data outside their assigned permissions. The vulnerability affects multiple version branches (2.0–2.1, 3.0, 4.0 before 4.0.8, and 4.1 before 4.1.4). Fix versions 4.0.8 and 4.1.4 address the authorization logic to restore proper privilege enforcement. No evidence of active exploitation in the wild has been reported.
Affected products
- Apache Doris 2.0.0 through 2.1.x, 3.0.0 through 3.0.x, 4.0.0 before 4.0.8, 4.1.0 before 4.1.4
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixes available in 4.0.8 and 4.1.4