CVE-2026-96443

NONE
Updated Sep 23, 2026
Apache Software Foundation
Parameter Value
Type CWE-829 (Inclusion of Functionality from Untrusted Source)
Vendor Apache Software Foundation
Public PoC No

Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.

Vulnerable Products

apache software foundation:apache doris