CVE-2026-96443 Overview
CVE-2026-96443 is a remote code execution vulnerability in Apache Doris caused by insufficient validation of the Java Database Connectivity (JDBC) driver URL. A privileged user can supply a crafted driver URL that the Frontend (FE) node loads, resulting in arbitrary code execution within the FE process. The flaw is categorized under [CWE-829: Inclusion of Functionality from Untrusted Control Sphere]. Apache Doris is a real-time analytical database, and the FE component handles metadata management, query planning, and client connections. Compromise of the FE grants an attacker control over query routing and cluster metadata.
Critical Impact
An authenticated privileged user can execute arbitrary code on the Apache Doris Frontend node by supplying a malicious JDBC driver URL, compromising the integrity and confidentiality of the analytical database cluster.
Affected Products
- Apache Doris (Frontend / FE component)
- Deployments exposing JDBC catalog or external table configuration to privileged users
- Analytical clusters where administrators can configure JDBC drivers
Discovery Timeline
- 2026-09-23 - CVE-2026-96443 published to the National Vulnerability Database (NVD)
- 2026-09-23 - Advisory posted to the Apache Mailing List Thread and Openwall OSS-Security Post
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-96443
Vulnerability Analysis
Apache Doris supports federated queries against external data sources through JDBC catalogs. When a privileged user configures a JDBC catalog, the FE accepts a driver URL that specifies where the JDBC driver JAR is located. The FE fetches this JAR and loads classes from it into the Java Virtual Machine (JVM) running the FE process. Insufficient validation of the driver URL allows an attacker-controlled location to be supplied. Once loaded, the malicious JAR executes code with the privileges of the FE service account. The issue maps to [CWE-829], reflecting the inclusion of functionality from an untrusted control sphere.
Root Cause
The FE does not enforce a strict allowlist of trusted driver URLs or validate the origin and integrity of the JAR referenced by the JDBC configuration. Any privileged user with permission to create or modify a JDBC catalog can direct the FE to download and instantiate arbitrary Java classes. Class initialization or static blocks within the crafted JAR execute during load, granting immediate code execution.
Attack Vector
An authenticated user with catalog-management privileges submits a JDBC catalog definition whose driver_url points to a JAR under attacker control, such as an HTTP server hosting a malicious driver class. When the FE resolves the driver, it downloads the JAR and loads a class named in the driver_class property. The static initializer of the class executes arbitrary Java code, including runtime commands via Runtime.getRuntime().exec(), on the FE host. See the Apache Mailing List Thread for the official advisory.
Detection Methods for CVE-2026-96443
Indicators of Compromise
- Unexpected outbound HTTP or HTTPS requests from the FE host retrieving JAR files from untrusted or external domains.
- New or modified JDBC catalog entries whose driver_url references non-corporate hosts, raw IP addresses, or file paths outside approved artifact repositories.
- Child processes spawned by the FE Java process, such as shells, curl, wget, or reverse-shell binaries.
Detection Strategies
- Audit Apache Doris FE logs for CREATE CATALOG and ALTER CATALOG statements that set JDBC driver properties, correlating on operator identity and source IP.
- Monitor the FE service account for anomalous process creation, file writes to temporary directories, and outbound network connections to non-approved destinations.
- Alert on JAR downloads by the FE process originating from URLs outside a maintained allowlist of Maven or artifact-repository hosts.
Monitoring Recommendations
- Ingest Apache Doris audit logs and FE process telemetry into a centralized analytics platform for correlation across catalog changes and host-level activity.
- Baseline normal JDBC catalog activity and alert on deviations in driver URL patterns or driver class names.
- Track privileged-account usage on Doris clusters and require ticketed change control for any JDBC catalog modification.
How to Mitigate CVE-2026-96443
Immediate Actions Required
- Upgrade Apache Doris to the fixed release referenced in the Apache Mailing List Thread advisory.
- Restrict catalog-management privileges to a minimal set of administrators and review current grants for unnecessary access.
- Inventory existing JDBC catalogs and remove or replace any entries with untrusted driver URLs.
Patch Information
Consult the Apache Mailing List Thread and the Openwall OSS-Security Post for the specific fixed version of Apache Doris addressing CVE-2026-96443. Apply the vendor-supplied patch across all FE nodes in the cluster and restart the FE service to load the updated code.
Workarounds
- Configure network egress controls on FE hosts to permit JAR downloads only from an internal artifact repository.
- Pre-stage approved JDBC driver JARs on FE nodes and disable or reject driver URLs pointing to external locations.
- Enable strict role-based access control so that only vetted administrators can create or modify JDBC catalogs.
# Example egress restriction using iptables on the FE host
# Allow outbound HTTPS only to an internal artifact repository
iptables -A OUTPUT -p tcp -d artifacts.internal.example.com --dport 443 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 443 -j REJECT
# Revoke broad catalog privileges in Apache Doris
REVOKE ADMIN_PRIV ON *.*.* FROM 'analyst'@'%';
GRANT SELECT_PRIV ON internal.*.* TO 'analyst'@'%';
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.