THE critical vulnerability CVE-2026-58319 affects Apache Doris version 2.1.0 due to improper authentication in the Frontend HTTP API, allowing unauthorized remote administrative operations. Currently, there is no confirmed exploitation in the wild. Users are advised to upgrade to version 3.1.0 or later to mitigate the risk. The flaw threatens data availability and cluster stability, as it permits unverified access to sensitive endpoints. An interim measure includes restricting network access to the affected service.
CVE-2026-58319 Exposes Doris Frontend to Unauthorised Access
CyberSIXT Evidence Panel
Article by CyberSIXT