Skip to main content
Vulnerability Database/CVE-2026-96443

CVE-2026-96443: Apache Doris JDBC URL RCE Vulnerability

CVE-2026-96443 is a remote code execution vulnerability in Apache Doris that exploits insufficient validation of JDBC driver URLs, enabling privileged users to execute arbitrary code on the FE server. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-96443 Overview

CVE-2026-96443 is a remote code execution vulnerability in Apache Doris caused by insufficient validation of the Java Database Connectivity (JDBC) driver URL. A privileged user can supply a crafted driver URL that the Frontend (FE) node loads, resulting in arbitrary code execution within the FE process. The flaw is categorized under [CWE-829: Inclusion of Functionality from Untrusted Control Sphere]. Apache Doris is a real-time analytical database, and the FE component handles metadata management, query planning, and client connections. Compromise of the FE grants an attacker control over query routing and cluster metadata.

Critical Impact

An authenticated privileged user can execute arbitrary code on the Apache Doris Frontend node by supplying a malicious JDBC driver URL, compromising the integrity and confidentiality of the analytical database cluster.

Affected Products

  • Apache Doris (Frontend / FE component)
  • Deployments exposing JDBC catalog or external table configuration to privileged users
  • Analytical clusters where administrators can configure JDBC drivers

Discovery Timeline

Technical Details for CVE-2026-96443

Vulnerability Analysis

Apache Doris supports federated queries against external data sources through JDBC catalogs. When a privileged user configures a JDBC catalog, the FE accepts a driver URL that specifies where the JDBC driver JAR is located. The FE fetches this JAR and loads classes from it into the Java Virtual Machine (JVM) running the FE process. Insufficient validation of the driver URL allows an attacker-controlled location to be supplied. Once loaded, the malicious JAR executes code with the privileges of the FE service account. The issue maps to [CWE-829], reflecting the inclusion of functionality from an untrusted control sphere.

Root Cause

The FE does not enforce a strict allowlist of trusted driver URLs or validate the origin and integrity of the JAR referenced by the JDBC configuration. Any privileged user with permission to create or modify a JDBC catalog can direct the FE to download and instantiate arbitrary Java classes. Class initialization or static blocks within the crafted JAR execute during load, granting immediate code execution.

Attack Vector

An authenticated user with catalog-management privileges submits a JDBC catalog definition whose driver_url points to a JAR under attacker control, such as an HTTP server hosting a malicious driver class. When the FE resolves the driver, it downloads the JAR and loads a class named in the driver_class property. The static initializer of the class executes arbitrary Java code, including runtime commands via Runtime.getRuntime().exec(), on the FE host. See the Apache Mailing List Thread for the official advisory.

Detection Methods for CVE-2026-96443

Indicators of Compromise

  • Unexpected outbound HTTP or HTTPS requests from the FE host retrieving JAR files from untrusted or external domains.
  • New or modified JDBC catalog entries whose driver_url references non-corporate hosts, raw IP addresses, or file paths outside approved artifact repositories.
  • Child processes spawned by the FE Java process, such as shells, curl, wget, or reverse-shell binaries.

Detection Strategies

  • Audit Apache Doris FE logs for CREATE CATALOG and ALTER CATALOG statements that set JDBC driver properties, correlating on operator identity and source IP.
  • Monitor the FE service account for anomalous process creation, file writes to temporary directories, and outbound network connections to non-approved destinations.
  • Alert on JAR downloads by the FE process originating from URLs outside a maintained allowlist of Maven or artifact-repository hosts.

Monitoring Recommendations

  • Ingest Apache Doris audit logs and FE process telemetry into a centralized analytics platform for correlation across catalog changes and host-level activity.
  • Baseline normal JDBC catalog activity and alert on deviations in driver URL patterns or driver class names.
  • Track privileged-account usage on Doris clusters and require ticketed change control for any JDBC catalog modification.

How to Mitigate CVE-2026-96443

Immediate Actions Required

  • Upgrade Apache Doris to the fixed release referenced in the Apache Mailing List Thread advisory.
  • Restrict catalog-management privileges to a minimal set of administrators and review current grants for unnecessary access.
  • Inventory existing JDBC catalogs and remove or replace any entries with untrusted driver URLs.

Patch Information

Consult the Apache Mailing List Thread and the Openwall OSS-Security Post for the specific fixed version of Apache Doris addressing CVE-2026-96443. Apply the vendor-supplied patch across all FE nodes in the cluster and restart the FE service to load the updated code.

Workarounds

  • Configure network egress controls on FE hosts to permit JAR downloads only from an internal artifact repository.
  • Pre-stage approved JDBC driver JARs on FE nodes and disable or reject driver URLs pointing to external locations.
  • Enable strict role-based access control so that only vetted administrators can create or modify JDBC catalogs.
bash
# Example egress restriction using iptables on the FE host
# Allow outbound HTTPS only to an internal artifact repository
iptables -A OUTPUT -p tcp -d artifacts.internal.example.com --dport 443 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 443 -j REJECT

# Revoke broad catalog privileges in Apache Doris
REVOKE ADMIN_PRIV ON *.*.* FROM 'analyst'@'%';
GRANT SELECT_PRIV ON internal.*.* TO 'analyst'@'%';

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.