← Vulnerability feed

Vulnerability record · CVE-2021-36749 · published 24 September 2021

CVE-2021-36749: Apache Druid HTTP InputSource authorization bypass allows local file read

Apache · Druid

Apache Druid's HTTP InputSource lets an authenticated user supply a file URL and read data from sources other than intended, including the local file system, with the privileges of the Druid server process. It matters most when Druid sits behind an application that permits the HTTP InputSource but blocks the Local InputSource, because the application-level restriction can be bypassed. The fix claimed for 0.21.0 under CVE-2021-26920 was not actually present in 0.21.0 or 0.21.1.

6.5 CVSS 3.1 Medium EPSS 81% · top 0.4% CWE-863 · Incorrect authorization
6.5CVSS 3.1 base score, v2 4.0
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid directly, since Druid also provides the Local InputSource, which allows the same level of access. But it is problematic when users interact with Druid indirectly through an application that allows users to specify the HTTP InputSource, but not the Local InputSource. In this case, users could bypass the application-level restriction by passing a file URL to the HTTP InputSource. This issue was previously mentioned as being fixed in 0.21.0 as per CVE-2021-26920 but was not fixed in 0.21.0 or 0.21.1.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw gives authenticated local file read with high confidentiality impact and a very high EPSS score, though it requires valid credentials and is not known to be exploited in the wild.

What it is

Apache Druid's HTTP InputSource lets an authenticated user supply a file URL and read data from sources other than intended, including the local file system, with the privileges of the Druid server process. It matters most when Druid sits behind an application that permits the HTTP InputSource but blocks the Local InputSource, because the application-level restriction can be bypassed. The fix claimed for 0.21.0 under CVE-2021-26920 was not actually present in 0.21.0 or 0.21.1.

Impact

An attacker with a Druid account gains read access to files reachable by the Druid server process, exposing configuration, credentials or other sensitive local data. The CVSS vector rates confidentiality impact as high with no integrity or availability effect.

Attack surface

Reached over the network through the Druid ingestion interface by an authenticated user; no user interaction is required. The flaw is an incorrect authorization check (CWE-863) on the HTTP InputSource, and the practical risk is highest where Druid is accessed indirectly through a front-end application.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.809 (99.6th percentile), indicating substantial predicted exploitation activity. References are vendor advisories and mailing list posts only, with no public exploit tag.

What to do

  • Upgrade Apache Druid past the affected 0.21.0 and 0.21.1 releases to a version where the HTTP InputSource restriction is actually enforced.
  • If upgrade is not immediate, restrict or disable the HTTP InputSource for untrusted users and block ingestion configurations that accept arbitrary file URLs.
  • Ensure Druid is never exposed directly to untrusted networks and that front-end applications cannot pass user-controlled URLs into the HTTP InputSource.
  • Run the Druid server process with a least-privilege account and limit its read access to sensitive local files and directories.
  • Audit Druid accounts and ingestion permissions, removing or narrowing access for users who do not need to define input sources.

Detection

  • Monitor Druid ingestion requests and task logs for HTTP InputSource configurations containing file:// or other local path URLs.
  • Alert on Druid server process reads of sensitive files such as /etc/passwd, configuration files or credential stores.
  • Review Druid audit and access logs for ingestion task creation by accounts that normally do not submit ingestion jobs.
  • Correlate outbound or local file access by the Druid process with ingestion task activity to spot unauthorized data reads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-36749 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-23906Apache druid improper authentication vulnerabilityAffected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-…EPSS 1.1%9.8CVE-2025-59390Apache druid vulnerabilityApache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is…EPSS 0.61%8.8CVE-2021-26919Apache druid vulnerabilityApache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissio…EPSS 23%8.8CVE-2021-25646Apache Druid JavaScript execution bypass enables remote code executionApache Druid supports executing user-provided JavaScript embedded in requests, a feature intended for high-trust environments and disabled by default…EPSS 99%analysed6.5CVE-2024-45537Apache druid improper input validation vulnerabilityApache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to se…EPSS 0.63%6.5CVE-2021-26920Apache druid vulnerabilityIn the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticate…EPSS 9.5%6.5CVE-2020-1958Apache druid injection vulnerabilityWhen LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsVali…EPSS 4.6%6.1CVE-2021-44791Apache druid cross-site scripting vulnerabilityIn Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2021-36749), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.