SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72524

HIGH · CVSS 8.8

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

An incorrect authorization vulnerability in Apache Doris allows authenticated users to bypass privilege checks, enabling unauthorized access to or modification of sensitive data. This issue affects versions 3.1.0 through 3.1.*, 4.0.0 through 4.0.7, and 4.1.0 through 4.1.3. Organizations using these versions should prioritize upgrading to 4.0.8 or 4.1.4 to mitigate potential data breaches.

CVE
CVE-2026-72524
Severity
HIGH
CVSS
8.8
EPSS
N/A
Apache

Original NVD Description

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3. Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.