Skip to main content
Vulnerability Database/CVE-2026-72524

CVE-2026-72524: Apache Doris Auth Bypass Vulnerability

CVE-2026-72524 is an authentication bypass flaw in Apache Doris that allows authenticated users to bypass privilege checks and access unauthorized data. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-72524 Overview

CVE-2026-72524 is an Incorrect Authorization vulnerability [CWE-863] in Apache Doris, an open-source real-time analytical database. The flaw allows an authenticated user to bypass privilege checks and access or modify data outside their assigned scope. The issue affects Apache Doris versions 3.1.0 through 3.1.*, 4.0.0 through 4.0.7, and 4.1.0 through 4.1.3. The Apache Doris project has released fixed versions 4.0.8 and 4.1.4.

Critical Impact

An authenticated attacker with low privileges can read or modify data belonging to other tenants or roles across an Apache Doris cluster over the network.

Affected Products

  • Apache Doris 3.1.0 through 3.1.*
  • Apache Doris 4.0.0 through 4.0.7
  • Apache Doris 4.1.0 through 4.1.3

Discovery Timeline

  • 2026-09-14 - CVE-2026-72524 published to the National Vulnerability Database (NVD)
  • 2026-09-14 - Coordinated disclosure posted to the Apache developer mailing list and OpenWall oss-security
  • 2026-09-14 - Record last modified in NVD

Technical Details for CVE-2026-72524

Vulnerability Analysis

Apache Doris enforces role-based access control across catalogs, databases, tables, columns, and rows. CVE-2026-72524 breaks that enforcement. An authenticated session with limited privileges can invoke operations that reach data the caller was never granted. Because the attack requires only valid credentials and network reachability to the Doris frontend, any legitimate analyst, service account, or compromised low-privilege user can weaponize it. Confidentiality, integrity, and availability of tenant data are all in scope, since the bypass permits both reads and modifications.

Root Cause

The defect is an Incorrect Authorization weakness [CWE-863]. The Apache Doris authorization layer performs privilege evaluation in a code path that does not correctly match the object or action being requested against the caller's granted privileges. As a result, the server accepts requests that should be denied. The fix ships in Apache Doris 4.0.8 and 4.1.4. The upstream advisory on the Apache mailing list and the OpenWall notice contain the authoritative change references.

Attack Vector

Exploitation occurs over the network against the Doris frontend service. The attacker must hold valid credentials for the target cluster, but no additional user interaction is required. Once authenticated, the attacker issues SQL or catalog operations that trigger the flawed authorization check, and the server returns or modifies data belonging to other users, roles, or catalogs. Public proof-of-concept exploit code is not currently available.

No verified exploit code is published. See the Apache Thread Discussion and the OpenWall OSS Security Update for the vendor's technical description.

Detection Methods for CVE-2026-72524

Indicators of Compromise

  • Successful queries in Doris fe.audit.log where the executing user references catalogs, databases, tables, or columns not present in their SHOW GRANTS output.
  • Unexpected SELECT, INSERT, UPDATE, or DELETE statements from service or analyst accounts that historically operated only on a narrow scope.
  • Frontend log entries showing authorization decisions that permit access to objects the account was never granted.

Detection Strategies

  • Baseline each Doris account's normal object access from fe.audit.log and alert on queries that touch previously unseen databases, tables, or columns.
  • Correlate authenticated Doris sessions with the current privilege grants pulled from the metadata catalog to flag any statement that operates outside those grants.
  • Monitor for privilege probing patterns such as rapid enumeration of catalogs, schemas, or system tables by low-privilege users.

Monitoring Recommendations

  • Forward fe.audit.log and frontend authentication logs to a centralized analytics platform for retention and query.
  • Alert on schema changes, grant modifications, and bulk data exports initiated by non-administrative accounts.
  • Track outbound data volumes from Doris frontends to identify large result sets returned to low-privilege sessions.

How to Mitigate CVE-2026-72524

Immediate Actions Required

  • Upgrade Apache Doris to 4.0.8 if running the 4.0.x branch, or to 4.1.4 if running the 4.1.x branch. The 3.1.x branch is affected without a listed fixed release; migrate to a supported fixed version.
  • Rotate credentials for any Doris account that may have been used by an attacker while the vulnerable version was exposed.
  • Review recent fe.audit.log entries for unauthorized data access predating the upgrade.

Patch Information

The Apache Doris project fixed CVE-2026-72524 in releases 4.0.8 and 4.1.4. Details are published in the Apache Thread Discussion and the OpenWall OSS Security Update. Users on 3.1.x should upgrade to a supported fixed branch.

Workarounds

  • Restrict network access to the Doris frontend so that only trusted application hosts and analyst workstations can reach it.
  • Reduce blast radius by tightening role grants and removing unused accounts until the upgrade is complete.
  • Enforce multi-factor authentication and short-lived credentials on any account permitted to reach the Doris frontend.
bash
# Verify the running Apache Doris frontend version
mysql -h <fe_host> -P 9030 -u root -p -e "SHOW FRONTENDS\G" | grep -i Version

# Confirm the upgrade landed on a fixed release
# Expected: 4.0.8 or later on the 4.0.x branch, or 4.1.4 or later on the 4.1.x branch

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.