{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/starrocks/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-80346"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["StarRocks"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["StarRocks"],"content_html":"\u003cp\u003eStarRocks contains a critical privilege escalation vulnerability, tracked as CVE-2026-80346, affecting the authorization logic for dropping legacy synchronous materialized views. Within the StarRocks codebase, most statement types are routed through the \u003ccode\u003eAuthorizerStmtVisitor\u003c/code\u003e to enforce access controls before execution. However, the \u003ccode\u003evisitDropMaterializedViewStatement\u003c/code\u003e method bypasses this mechanism for legacy synchronous views.\u003c/p\u003e\n\u003cp\u003eBecause legacy synchronous materialized views are stored as rollup indexes within an \u003ccode\u003eOlapTable\u003c/code\u003e object rather than as standalone \u003ccode\u003eMaterializedView\u003c/code\u003e objects, the system fails to trigger the \u003ccode\u003eAuthorizer.checkMaterializedViewAction\u003c/code\u003e logic. Instead, the process proceeds through \u003ccode\u003eAlterJobMgr.processDropMaterializedView\u003c/code\u003e and \u003ccode\u003eMaterializedViewHandler\u003c/code\u003e, neither of which contains authorization checks. Consequently, any authenticated user can successfully execute a command to drop a legacy synchronous materialized view in any database, regardless of their actual permission set. This issue presents a significant availability risk, as an attacker can silently remove materialized views, causing downstream query failures and data inconsistencies.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows any authenticated account to delete legacy materialized views belonging to any database, despite lacking the necessary grants on the views, the underlying base tables, or the target databases. This results in unauthorized data modification and potential service disruption for users relying on those views for reporting or query performance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching StarRocks to a version where privilege checks are correctly implemented in \u003ccode\u003eMaterializedViewHandler\u003c/code\u003e for legacy objects. In the interim, restrict access to the StarRocks environment to strictly authorized users, as any authenticated account currently possesses the ability to drop these materialized views. Audit current database schemas to identify all legacy synchronous materialized views to assess the potential impact of potential deletion attempts.\u003c/p\u003e\n","date_modified":"2026-08-26T22:24:21Z","date_published":"2026-08-26T22:24:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-starrocks-privilege-bypass/","summary":"A privilege escalation vulnerability (CVE-2026-80346) in StarRocks allows any authenticated user to drop legacy synchronous materialized views without required authorization checks.","title":"StarRocks Privilege Bypass in Legacy Materialized View Deletion","url":"https://feed.craftedsignal.io/briefs/2026-08-starrocks-privilege-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - StarRocks","version":"https://jsonfeed.org/version/1.1"}