CVE-2026-80346 – StarRocks

CVSS 7.1 IMPORTANT Zero Day – Immediate Deployment

“A missing authorization check lets any authenticated user delete materialized views they do not own.”

StarRocks contains a High-severity authorization flaw affecting legacy synchronous materialized views. CVE-2026-80346 allows any authenticated account to drop a legacy synchronous materialized view in any database without privileges on the view, base table, or database. The CVSS score is 7.1, which is High severity.

Public proof-of-concept material is available for the vulnerability.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-862
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.