Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE. | |
| Title | Apache Doris: JDBC driver URL validation bypass leads to remote code execution | |
| Weaknesses | CWE-829 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-23T09:35:33.800Z
Reserved: 2026-09-23T09:01:29.491Z
Link: CVE-2026-96443
No data.
Status : Received
Published: 2026-09-23T10:17:08.943
Modified: 2026-09-23T10:17:08.943
Link: CVE-2026-96443
No data.
OpenCVE Enrichment
No data.
Weaknesses