StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including statements containing credentials.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including statements containing credentials. | |
| Title | StarRocks Query Detail Endpoint Returns Every User's Query History | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T16:19:08.668Z
Reserved: 2026-08-28T12:14:57.815Z
Link: CVE-2026-82306
No data.
Status : Received
Published: 2026-08-28T20:20:20.947
Modified: 2026-08-28T20:20:20.947
Link: CVE-2026-82306
No data.
OpenCVE Enrichment
Updated: 2026-08-28T22:30:17Z
Weaknesses