logo

Apache Doris SQL Injection Vulnerability CVE-2025-66336

ID: 732bafa9-9933-5b2b-86c2-cd047aab76be

STIX ID: report--732bafa9-9933-5b2b-86c2-cd047aab76be

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Do Son

...
...

**Apache Doris MCP Server (CVE-2025-66336)**: A SQL injection in the MCP Server metadata query path can allow attackers to bypass authentication and access restricted database metadata; the flaw affects versions 0.1.0 up to (but not including) 0.6.1 and is patched in 0.6.1 — administrators should upgrade immediately and ensure authentication remains enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.