CVE-2026-96443: Apache Software Foundation Apache Doris

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.

Affected products

Published 2026-09-23. Last modified 2026-09-23.