Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-58319: Apache Doris: Unauthenticated Access to Administrative APIs
CVE-2026-58319 · published 2 months ago
Summary
Apache Doris versions before 3.1.0 have a security issue. An attacker without a password can access and control important settings, which could make the system unstable or unavailable. To fix this, upgrade to Apache Doris 3.1.0 or later.
What to do
- Update apache software foundation apache doris to version 3.1.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache doris | < 3.1.0 |
Original advisory text
Apache Doris: Improper Authentication in Frontend HTTP API
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service.
This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.
This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published14 Jul 2026
Updated25 Sep 2026
First seen14 Jul 2026
Track software like this
Free during beta