- CVE: CVE-2026-58319
- CVSS: 9.1 (Critical · CVSSv3)
- Product: Apache Software Foundation Apache Doris
- Affected: 2.1.0
- Impact: Apache Doris: Improper Authentication in Frontend HTTP API
- Status: No confirmed exploitation yet
- Patched in: 3.1.0
- EPSS: 0.6% (30-day)
- Action: Update to 3.1.0 now
TL;DR
The Apache Doris project has patched a critical Apache Doris vulnerability, tracked as CVE-2026-58319. Some Frontend (FE) HTTP REST admin APIs were reachable without authentication. As a result, a remote attacker could run administrative operations and disrupt the cluster.
Why It Matters
Apache Doris is a widely deployed real-time analytics database. It powers SQL analytics, lakehouse acceleration, and hybrid search for many organizations. Consequently, an unauthenticated path to admin functions puts data availability and cluster stability at direct risk.
How the Attack Works
The flaw stems from an improper authentication check on the FE HTTP service. Certain administrative REST endpoints did not verify the caller’s identity. Therefore, an attacker with network access to the FE HTTP port could send unauthorized admin requests. The advisory warns this could affect cluster integrity and availability, potentially causing instability or denial of service. This report omits endpoint details and proof-of-concept steps.
Affected Versions
The Apache Doris vulnerability affects versions from 2.1.0 up to, but not including, 3.1.0.
Exploitation Status
The Apache advisory does not confirm any in-the-wild exploitation or public proof-of-concept at this time. No such activity has been reported.
Patch and Mitigation
Apache urges users to upgrade to Doris 3.1.0 or later, which fixes the issue. Grab the fixed release from the official Apache Doris download page. As an interim measure, restrict network access to the FE HTTP service and place it behind trusted network controls.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.