Known Vulnerabilities for Doris by Apache
Listed below are 2 of the newest known vulnerabilities associated with "Doris" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72524 json | Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or m... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-68570 json | Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-58319 json | Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attac... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2025-66336 json | Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is d... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2022-23942 json | Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to ... | 7.5 - HIGH | 2022-04-26 | 2022-05-06 |