CVE-2026-72524: Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to.
This issue affects Apache Doris: from 3.1.0 through 3.1., from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3.
Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Doristo a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
Apache Doristo a version that resolves this vulnerability.Fixed in 4.1.4
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Doris versions from 3.1.0 through 3.1.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3 are affected.
What level of access does an attacker need?
An attacker must be authenticated as a low-privilege Apache Doris user. That user can bypass privilege checks to read, modify, or drop tables they would not normally be authorized to access.
What remediation is available?
Upgrade to Apache Doris 4.0.8 or 4.1.4, which fix the issue.