{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-31377","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2026-03-09T05:56:59.960Z","datePublished":"2026-09-23T09:04:56.122Z","dateUpdated":"2026-09-23T17:08:10.651Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2026-09-23T09:04:56.122Z"},"title":"Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service","problemTypes":[{"descriptions":[{"description":"CWE-287: Improper Authentication","lang":"en","cweId":"CWE-287","type":"CWE"}]}],"source":{"discovery":"UNKNOWN"},"affected":[{"vendor":"Apache Software Foundation","product":"Apache Doris","modules":["Frontend (FE) meta service"],"programFiles":["fe/fe-core/src/main/java/org/apache/doris/httpv2/meta/MetaService.java"],"versions":[{"status":"affected","version":"2.0.0","lessThan":"4.0.8","versionType":"semver"},{"status":"affected","version":"4.1.0","lessThan":"4.1.4","versionType":"semver"},{"status":"unaffected","version":"0","lessThan":"2.0.0","versionType":"semver"},{"status":"unaffected","version":"4.0.8","lessThan":"4.1.0","versionType":"semver"},{"status":"unaffected","version":"4.1.4","lessThan":"*","versionType":"semver"}],"defaultStatus":"unknown"}],"descriptions":[{"value":"An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints.\n\n\n\nThe affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information.\n\n\n\nThis issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Versions 1.2.x and earlier are not affected by this header-trust vulnerability.\n\n\n\n\nUsers are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.","lang":"en","supportingMedia":[{"type":"text/html","base64":false,"value":"An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints.<br><br><p><span>The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information.</span></p><p><span>This issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Versions 1.2.x and earlier are not affected by this header-trust vulnerability.</span><br></p><p>Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.</p>"}]}],"references":[{"url":"https://lists.apache.org/thread/rf4ocqmzxvnwnxpsooj2lkzjl68b1m9q","tags":["vendor-advisory"]}],"metrics":[{"other":{"type":"Textual description of severity","content":{"text":"important"}},"scenarios":[{"lang":"en","value":"GENERAL"}]},{"scenarios":[{"lang":"en","value":"GENERAL"}],"format":"CVSS","cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"HIGH","baseScore":7.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}}],"credits":[{"lang":"en","value":"Mapta / BugBunny_ai","type":"reporter"},{"lang":"en","value":"Calvin Kirs, Security Researcher at SelectDB","type":"reporter"},{"lang":"en","value":"Vlary (Huntree Security Team)","type":"reporter"},{"lang":"en","value":"Vladimir Tokarev (g1nd1l4)","type":"reporter"},{"lang":"en","value":"lalalala5678","type":"reporter"},{"lang":"en","value":"4ra2n (A code security AI agent)","type":"reporter"},{"lang":"en","value":"Fakile Emmanuel","type":"reporter"},{"lang":"en","value":"Fried Chicken","type":"reporter"}],"x_generator":{"engine":"Vulnogram 1.0.3"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-23T14:06:33.070831Z","id":"CVE-2026-31377","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-23T14:06:44.071Z"}},{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/23/10"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-09-23T17:08:10.651Z"}}]}}