Improper Authentication Vulnerability in Apache Doris Frontend Meta Service
CVE-2026-31377
7.5HIGH
What is CVE-2026-31377?
An Improper Authentication vulnerability in the Apache Doris Frontend meta service presents a security risk by allowing unauthenticated remote attackers to access sensitive internal metadata service endpoints. The affected endpoints depend on client-supplied node information for authentication, lacking adequate verification of the requesting party. This oversight permits attackers, under specific network configurations, to circumvent established access controls and potentially disclose sensitive cluster information. Users are strongly advised to upgrade to versions 4.0.8 or 4.1.4 to mitigate this issue.
Affected Version(s)
Apache Doris 2.0.0 < 4.0.8
Apache Doris 4.1.0 < 4.1.4
Apache Doris 0 < 2.0.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mapta / BugBunny_ai
Calvin Kirs, Security Researcher at SelectDB
Vlary (Huntree Security Team)
Vladimir Tokarev (g1nd1l4)
lalalala5678
4ra2n (A code security AI agent)
Fakile Emmanuel
Fried Chicken