Junglewise Threat Intelligence

CVE-2026-82276: StarRocks authentication bypass in REST handlers

CVE-2026-82276 · Severity: medium · CVSS 5.3 · Published 2026-08-28

Technologies: StarRocks. Vendors: StarRocks.

Executive brief

StarRocks is an open-source analytics database engine used for fast query processing on data lakes. Through version 4.0.13, five REST API endpoints can be accessed without authentication, allowing attackers to retrieve sensitive cluster topology, database schema information, and system statistics without credentials. This exposes operational details that could aid further attacks.

Technical details

The vulnerability is an authentication bypass in REST handler classes that override the execute() method directly instead of implementing the secure executeWithoutPassword() method. Five affected handler classes fail to enforce authentication on their endpoints. An unauthenticated attacker on the network can send HTTP requests to six REST endpoints on the frontend HTTP port to retrieve cluster topology, database metadata, JVM statistics, and version information. No authentication credentials or user interaction is required. Patches are expected to be available in versions after 4.0.13.

Affected products

  • StarRocks StarRocks through 4.0.13

Timeline

  • 2026-08-28: disclosed

References

Related threats