SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-58319

CRITICAL · CVSS 9.1 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Certain Apache Doris FE HTTP REST administrative APIs are vulnerable due to inadequate authentication, allowing unauthenticated attackers with network access to execute unauthorized administrative operations. This could compromise cluster integrity and availability, potentially resulting in instability or denial of service. Organizations using Apache Doris versions prior to 3.1.0 should prioritize upgrading to version 3.1.0 or later to mitigate this critical risk.

CVE
CVE-2026-58319
Severity
CRITICAL
CVSS
9.1
EPSS
0.51%
Apache

Original NVD Description

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. Users are advised to upgrade to Apache Doris 3.1.0 or later.

Related CVEs

Other vulnerabilities affecting the same vendor(s)