Authorization Flaw in Apache Doris Leads to Data Exposure Risks
CVE-2026-68570

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-68570?

An incorrect authorization vulnerability in Apache Doris allows an authenticated user to bypass necessary privilege checks. This flaw enables unauthorized access to sensitive data that should be restricted, leading to potential disclosure of confidential information. Users are advised to upgrade their Apache Doris version to 4.0.8 or 4.1.4 to mitigate this risk effectively.

Affected Version(s)

Apache Doris 2.0.0 <= 2.1.*

Apache Doris 3.0.0 <= 3.0.*

Apache Doris 4.0.0 < 4.0.8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Calvin Kirs, Security Researcher at SelectDB
.