Junglewise Threat Intelligence

CVE-2026-80346: StarRocks authorization bypass in legacy materialized view drop

CVE-2026-80346 · Severity: high · CVSS 7.1 · Published 2026-08-26

Technologies: StarRocks. Vendors: StarRocks.

Executive brief

StarRocks is an analytics database used to query data across data lakes. An authenticated user without proper permissions can drop legacy synchronous materialized views (cached query results) belonging to any database, bypassing authorization checks entirely. This allows unauthorized deletion of critical cached data structures that other applications may depend on.

Technical details

StarRocks has a privilege-checking gap in the DROP MATERIALIZED VIEW statement handler. Modern (asynchronous) materialized views are stored as MaterializedView objects and properly routed through the AuthorizerStmtVisitor for privilege validation. However, legacy synchronous materialized views are stored as rollup indices on OlapTable objects; when dropped, the code path bypasses authorization and directly calls AlterJobMgr.processDropMaterializedView and MaterializedViewHandler, neither of which perform authorization checks. Any authenticated user can therefore drop a legacy synchronous materialized view without holding any grant on the view, base table, or database. The vulnerability requires authentication but no special privileges or user interaction.

Affected products

  • StarRocks StarRocks <UNKNOWN>

Timeline

  • 2026-08-26: disclosed

References

Related threats