CVE-2026-31377
Last modified
CVE-2026-31377 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information. This issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information. This issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Versions 1.2.x and earlier are not affected by this header-trust vulnerability. Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache Doris | >= 2.0.0, < 4.0.8; >= 4.1.0, < 4.1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-31377?
How severe is CVE-2026-31377?
How do I fix CVE-2026-31377?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-31354Multiple authenticated stored cross-site scripting (XSS) vul…5.4
- CVE-2026-3136An improper authorization vulnerability in GitHub Trigger Co…9.8
- CVE-2026-31368AiAssistant is affected by type privilege bypass, successful…7.8
- CVE-2026-31369PcManager is affected by type privilege bypass, successful e…3.2
- CVE-2026-3137A security vulnerability has been detected in CodeAstro Food…7.8
- CVE-2026-31370Honor E APP is affected by information leak vulnerability, s…6.3
- CVE-2026-31378Improper Input Validation vulnerability in Apache OFBiz. Th…6.5
- CVE-2026-31379Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2026-3138The Product Filter for WooCommerce by WBW plugin for WordPre…6.5
- CVE-2026-31380Improper Neutralization of Special Elements used in an Expre…6.5
- CVE-2026-31381An attacker can extract user email addresses (PII) exposed i…5.3
- CVE-2026-31382The error_description parameter is vulnerable to Reflected X…6.1
Are you affected by CVE-2026-31377?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
