CVE-2026-82306 MEDIUM

CVE-2026-82306: StarRocks Query Detail Endpoint Returns Every User's Query History

Vendor Starrocks
Product starrocks
Weakness CWE-200 · Info exposure
Published August 28, 2026
Last update August 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including statements containing credentials.

Key dates

02Disclosure timeline

August 28, 2026 CVE published

Related vulnerabilities

04Related CVE