Severity: moderate 

Affected versions:

- Apache Doris 2.0.5 through 4.1.3

Description:

Insufficient validation of the JDBC driver URL in Apache Doris allows a 
privileged user to achieve remote code execution on the FE.

Credit:

zhaoyudi (nebula LAB) (finder)

References:

https://doris.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-96443


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to