Junglewise Threat Intelligence

CVE-2026-96443: Apache Doris JDBC driver URL validation bypass

CVE-2026-96443 · Severity: medium · CVSS 6.5 · Published 2026-09-23

Vendors: Apache.

Executive brief

Apache Doris is a distributed data warehouse used for analytics. A privileged user can bypass URL validation when configuring JDBC database drivers, allowing them to execute arbitrary code on the system's front-end node. This requires the attacker to have elevated privileges within Doris.

Technical details

The vulnerability involves insufficient validation of JDBC driver URLs in Apache Doris, allowing a privileged user to inject malicious configurations that execute remote code on the front-end (FE) node. The attack requires high-level privileges within Doris and leverages the JDBC connection mechanism. A fix is available in newer versions.

Affected products

  • Apache Doris 2.0.5 through 4.1.3

Timeline

  • 2026-09-23: disclosed

References

Related threats