---
id: CVE-2026-31377
title: >-
  An Improper Authentication vulnerability in the Apache Doris Frontend (FE)
  meta service allows an unauthenticated remote attacker to access internal
  metadata service endpoints.




  The affected endpoints relied on client-supplied node inf…
summary: >-
  An Improper Authentication vulnerability in the Apache Doris Frontend (FE)
  meta service allows an unauthenticated remote attacker to access internal
  metadata service endpoints.




  The affected endpoints relied on client-supplied node inf…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-287
vendor: Apache Software Foundation
product: Apache Doris
affected:
  - apache_doris >= 2.0.0 < 4.0.8
  - apache_doris >= 4.1.0 < 4.1.4
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:58:26.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-31377'
references:
  - url: 'https://lists.apache.org/thread/rf4ocqmzxvnwnxpsooj2lkzjl68b1m9q'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/23/10'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.00647
epssPercentile: 0.49622
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-23T14:06:33.070831Z'
ingestedAt: '2026-09-23T09:21:16.966Z'
---

## Overview

An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints.



The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information.



This issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Versions 1.2.x and earlier are not affected by this header-trust vulnerability.




Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
