CVE-2026-96443: Apache Software Foundation Apache Doris
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.
Affected products
- Apache Software Foundation Apache Doris: from 2.0.5, up to and including 4.1.3
Published 2026-09-23. Last modified 2026-09-23.