← Vulnerability feed

Vulnerability record · CVE-2024-26307 · published 21 March 2024

CVE-2024-26307: Apache doris race condition vulnerability

Apache · Doris

Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4. Users are recommended to upgrade to version 2.0.4, which fixes the issue.

5.3 CVSS 3.1 Medium EPSS 0.22% · top 88.6% CWE-362 · Race condition
5.3CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4. Users are recommended to upgrade to version 2.0.4, which fixes the issue.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-26307 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27438Apache doris download of code without integrity check vulnerabilityDownload of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting …EPSS 0.96%9.8CVE-2023-41313Apache doris vulnerabilityThe authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 +…EPSS 1.0%9.1CVE-2026-58319Apache doris missing authentication for critical function vulnerabilityCertain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …EPSS 0.75%8.2CVE-2023-41314Apache doris incorrect authorization vulnerabilityThe api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Plea…EPSS 0.90%7.5CVE-2022-23942Apache doris hard-coded credentials vulnerabilityApache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.EPSS 3.5%5.4CVE-2024-48019Apache doris path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in …EPSS 1.0%5.5CVE-2025-39964Linux kernel af_alg race condition allows concurrent socket writesThe Linux kernel's af_alg crypto socket implementation did not prevent two concurrent writes to the same socket, allowing data to be interleaved unpr…KEVEPSS 1.00%analysed7.0CVE-2025-62215Windows Kernel race condition and double free privilege escalationA race condition combined with a double free in the Windows Kernel lets a locally authenticated attacker corrupt kernel memory and elevate privileges…KEVEPSS 6.0%analysed

Source: NIST National Vulnerability Database (record CVE-2024-26307), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.