云虫漏洞情报

CVE-2026-82276 - StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints on the frontend HTTP port to disclose cluster topology, database metadata, JVM statistics, and version information without credentials. - 漏洞详情

漏洞编号:CVE-2026-82276

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-82276

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-306

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints on the frontend HTTP port to disclose cluster topology, database metadata, JVM statistics, and version information without credentials.

相关链接

相关漏洞

« 返回首页