Junglewise Threat Intelligence

CVE-2026-72524: Apache Doris authorization bypass in privilege checks

CVE-2026-72524 · Severity: high · CVSS 8.8 · Published 2026-09-14

Vendors: Apache.

Executive brief

Apache Doris is a real-time analytics database platform used to process and query large volumes of data. An authenticated user with limited permissions can bypass security controls to read, modify, or delete database tables they should not have access to, potentially exposing sensitive business data or disrupting operations.

Technical details

This is an authorization bypass vulnerability in Apache Doris that allows an authenticated user to escalate privileges and bypass privilege checks. The vulnerability affects versions 3.1.0 through 3.1.*, 4.0.0 through 4.0.7, and 4.1.0 through 4.1.3. An attacker with valid credentials but limited privileges can read, write, or drop arbitrary tables they are not authorized to access. The attack requires valid authentication to the Doris instance but no additional user interaction. Patches are available in versions 4.0.8 and 4.1.4.

Affected products

  • Apache Doris 3.1.0 through 3.1.*, 4.0.0 through 4.0.7, 4.1.0 through 4.1.3

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in versions 4.0.8 and 4.1.4

References