CVE-2026-72524
EUVD-2026-7735314.09.2026, 10:17
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3. Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apache | doris | 3.1.0 ≤ 𝑥 ≤ 3.1.* | CNA |
| apache | doris | 4.0.0 ≤ 𝑥 ≤ 4.0.7 | CNA |
| apache | doris | 4.1.0 ≤ 𝑥 ≤ 4.1.3 | CNA |