PatchSiren

StarRocks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM StarRocks CVE published 2026-08-28

CVE-2026-82276

CVE-2026-82276 is an authentication bypass vulnerability in StarRocks through version 4.0.13, affecting five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints to disclose cluster topology, database metadata, JVM statistics, and version information without credentials. This vulnerability allows unauthor [truncated]

HIGH StarRocks CVE published 2026-08-26

CVE-2026-80346

StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. This issue allows any authenticated account to drop a legacy synchronous materialized view belonging to any database without holding the necessary grants. The vulnerability impacts data integrity and confidentiality, as unauthorized drops can lead to data loss or corruption. Defenders must verify exposure of lega [truncated]