---
id: CVE-2026-68570
title: >-
  Incorrect Authorization vulnerability in Apache Doris allows an authenticated
  user to bypass privilege checks and access data they are not authorized to
  read, resulting in unauthorized disclosure of information.




  This issue affects Apa…
summary: >-
  Incorrect Authorization vulnerability in Apache Doris allows an authenticated
  user to bypass privilege checks and access data they are not authorized to
  read, resulting in unauthorized disclosure of information.




  This issue affects Apa…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: Apache Software Foundation
product: Apache Doris
affected:
  - apache_doris >= 2.0.0 <= 2.1.*
  - apache_doris >= 3.0.0 <= 3.0.*
  - apache_doris >= 4.0.0 < 4.0.8
  - apache_doris >= 4.1.0 < 4.1.4
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:58:48.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-68570'
references:
  - url: 'https://lists.apache.org/thread/rp2gr6d7rb4y8slxh3fojmhb1rl5ms03'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/14/2'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T19:38:04.435786Z'
ingestedAt: '2026-09-14T15:23:07.463Z'
epss: 0.00382
epssPercentile: 0.2936
---

## Overview

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information.



This issue affects Apache Doris: from 2.0.0 through 2.1.*, from 3.0.0 through 3.0.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4.



Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
