CVE-2026-82276: StarRocks Frontend REST Handlers Bypass the Base Class Authentication Gate

Published Aug 28, 2026
·
Updated

StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints on the frontend HTTP port to disclose cluster topology, database metadata, JVM statistics, and version information without credentials.

Affected Software

1 affected component
StarRocks StarRocks Frontend<=4.0.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade StarRocks Frontend to a version that resolves this vulnerability.

    Fixed in 4.0.13

Event History

Aug 28, 2026
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

StarRocks Frontend instances through 4.0.13 are affected if their frontend HTTP port is reachable by an attacker. No credentials or user interaction are required.

2

What information can an unauthenticated attacker obtain?

The affected REST endpoints can disclose cluster topology, database metadata, JVM statistics, and StarRocks version information. The reported impact is limited to information disclosure; integrity and availability impact are not indicated.

3

How can I determine whether my deployment is affected?

Check whether the StarRocks Frontend version is 4.0.13 or earlier and whether its HTTP port exposes the affected REST handlers to untrusted network clients. The issue affects five handler classes and six unauthenticated endpoints.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203