StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including statements containing credentials.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Starrocks
Starrocks starrocks |
|
| Vendors & Products |
Starrocks
Starrocks starrocks |
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including statements containing credentials. | |
| Title | StarRocks Query Detail Endpoint Returns Every User's Query History | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-28T16:19:08.668Z
Updated: 2026-08-31T18:54:41.650Z
Reserved: 2026-08-28T12:14:57.815Z
Link: CVE-2026-82306
Updated: 2026-08-31T16:23:28.093Z
Status : Received
Published: 2026-08-28T20:20:20.947
Modified: 2026-08-31T19:17:18.527
Link: CVE-2026-82306
No data.