Apache Doris FE Meta Service Improper Auth (v2.0-4.1.3, fixed 4.0.8/4.1.4)
CVE-2026-31377 Published on September 23, 2026
Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service
An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints.
The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information.
This issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Versions 1.2.x and earlier are not affected by this header-trust vulnerability.
Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
Vulnerability Analysis
CVE-2026-31377 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an authentification Vulnerability?
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVE-2026-31377 has been classified to as an authentification vulnerability or weakness.
Products Associated with CVE-2026-31377
Want to know whenever a new CVE is published for Apache Doris? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Doris:- Version 2.0.0 and below 4.0.8 is affected.
- Version 4.1.0 and below 4.1.4 is affected.
- Before 2.0.0 is unaffected.
- Version 4.0.8 and below 4.1.0 is unaffected.
- Version 4.1.4 and below * is unaffected.