securityonline.info 7/20/2026, 2:51:04 PM · external

CVE-2026-58319 Exposes Doris Frontend to Unauthorised Access

CVE-2026-58319 Exposes Doris Frontend to Unauthorised Access
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

THE critical vulnerability CVE-2026-58319 affects Apache Doris version 2.1.0 due to improper authentication in the Frontend HTTP API, allowing unauthorized remote administrative operations. Currently, there is no confirmed exploitation in the wild. Users are advised to upgrade to version 3.1.0 or later to mitigate the risk. The flaw threatens data availability and cluster stability, as it permits unverified access to sensitive endpoints. An interim measure includes restricting network access to the affected service.

View full article

Article by CyberSIXT