CVE-2026-68570 Overview
CVE-2026-68570 is an Incorrect Authorization vulnerability [CWE-863] in Apache Doris. An authenticated user can bypass privilege checks and read data they are not authorized to access. The flaw results in unauthorized disclosure of information stored within the analytical database.
The issue affects Apache Doris versions 2.0.0 through 2.1., 3.0.0 through 3.0., 4.0.0 before 4.0.8, and 4.1.0 before 4.1.4. The Apache Doris project recommends upgrading to release 4.0.8 or 4.1.4, which contain the fix.
Critical Impact
An authenticated user with low privileges can access confidential data belonging to other users or tenants, undermining Apache Doris tenant isolation and data governance controls.
Affected Products
- Apache Doris 2.0.0 through 2.1.* (all releases)
- Apache Doris 3.0.0 through 3.0.* (all releases)
- Apache Doris 4.0.0 before 4.0.8 and 4.1.0 before 4.1.4
Discovery Timeline
- 2026-09-14 - CVE-2026-68570 published to NVD
- 2026-09-14 - Apache Software Foundation publishes security advisory on the Apache security mailing list
- 2026-09-14 - Last updated in NVD database
Technical Details for CVE-2026-68570
Vulnerability Analysis
Apache Doris is a distributed, real-time analytical database that enforces role-based access control on databases, tables, columns, and rows. CVE-2026-68570 breaks that enforcement model. A user who successfully authenticates to the cluster can issue requests that reach protected data without triggering the expected authorization check.
The outcome is a confidentiality-only impact. Integrity and availability of the database are unaffected, but a low-privileged account can read tables or columns reserved for other roles. In multi-tenant deployments, this exposes cross-tenant data through a legitimate query path rather than through injection or code execution.
The vulnerability is exploitable over the network against the Doris frontend service. It requires valid credentials but no user interaction, so any account with query access to the cluster is a viable exploitation vector.
Root Cause
The defect is classified as Incorrect Authorization [CWE-863]. The Apache Doris privilege engine evaluates access decisions inconsistently for certain request paths, so the authorization check either fails to run or returns an incorrect allow decision. As a result, the query planner or executor proceeds to fetch data the caller should not see.
Attack Vector
An authenticated attacker connects to the Doris frontend using the MySQL-compatible protocol or the HTTP API. The attacker issues queries that target databases, tables, or columns outside their granted privilege set. Because the authorization decision is incorrect, Doris returns the protected rows or metadata to the attacker's session. No malformed payload or memory corruption is required; the exploit uses supported query syntax through an authenticated channel. Refer to the Apache Security Mailing List Thread and the OpenWall OSS Security Update for the vendor's technical description.
Detection Methods for CVE-2026-68570
Indicators of Compromise
- Successful queries in Doris audit logs that reference databases, tables, or columns outside the executing user's granted privileges.
- Sudden increases in SELECT, SHOW, or metadata queries from low-privileged accounts against sensitive schemas.
- Result sets returned to accounts that historically received Access denied errors for the same objects.
Detection Strategies
- Enable and centralize Apache Doris frontend audit logs, then compare each query's target objects against the executing user's GRANT set to flag mismatches.
- Baseline normal per-user query patterns and alert on new access to sensitive schemas, especially by service or reporting accounts.
- Correlate authentication events with query telemetry to identify accounts issuing broad discovery queries such as SHOW DATABASES or SHOW TABLES followed by targeted reads.
Monitoring Recommendations
- Forward Doris audit and frontend logs into a centralized analytics platform for long-term retention and cross-source correlation.
- Monitor for privilege enumeration commands (SHOW GRANTS, SHOW ROLES) executed by accounts that do not perform administrative duties.
- Track cluster version strings reported by Doris frontends to confirm every node runs a patched release.
How to Mitigate CVE-2026-68570
Immediate Actions Required
- Upgrade all Apache Doris frontend and backend nodes to version 4.0.8 or 4.1.4, matching the branch currently deployed.
- Inventory clusters still on the 2.0.x, 2.1.x, or 3.0.x branches; these lines do not have a fixed release listed in the advisory and should be migrated to a supported branch.
- Rotate credentials for any Doris accounts whose activity in audit logs suggests access to data outside their granted privileges.
- Review and tighten GRANT statements so that each role holds only the minimum privileges required.
Patch Information
The Apache Doris project has released fixed versions 4.0.8 and 4.1.4. Users on the 4.0.x branch should upgrade to 4.0.8, and users on the 4.1.x branch should upgrade to 4.1.4. Full details are available in the Apache Security Mailing List Thread and the OpenWall OSS Security Update.
Workarounds
- Restrict network access to Doris frontend ports so that only trusted application hosts and administrators can authenticate.
- Reduce the blast radius by revoking broad privileges from shared or application service accounts until upgrades are complete.
- Enable audit logging on every frontend node and review it daily for cross-privilege access patterns until all clusters are patched.
# Verify Apache Doris version on each frontend node
mysql -h <fe_host> -P 9030 -u root -p -e "SHOW FRONTENDS\G"
# Review privileges assigned to a specific user
mysql -h <fe_host> -P 9030 -u root -p -e "SHOW GRANTS FOR 'app_user'@'%';"
# Revoke overly broad privileges as a temporary hardening step
mysql -h <fe_host> -P 9030 -u root -p -e "REVOKE SELECT_PRIV ON *.*.* FROM 'app_user'@'%';"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.