SPLASH 2026
Sun 4 - Fri 9 October 2026 Oakland, California, United States
co-located with SPLASH/ISSTA 2026

This program is tentative and subject to change.

Tue 6 Oct 2026 16:24 - 16:42 at Junior Ballroom 3&4 - Smart Contracts and Blockchain Chair(s): Chandrakana Nandi

Access control in DBMSs is critical for ensuring data security and integrity. However, the increasing complexity of its implementation often introduces broken access control (BAC) vulnerabilities. These vulnerabilities can lead to severe consequences, including privilege escalation, unauthorized data access, or even full compromise of the DBMS. Existing manual testing for BAC vulnerabilities is time-consuming and incomplete. Automated methods like static analysis also struggle in DBMSs, as static rules are difficult to apply to multi-level and dynamically changing privileges.

In this paper, we propose Beacon, which detects BAC vulnerabilities by validating the consistency between SQL operations and system catalogs. Our key insight is that the visibility of objects in the system catalogs is consistent with the user's access control: if an object is invisible to a user in the system catalogs, the user should not have any access privileges on that. Any inconsistency suggests that a user is exceeding their privileges, indicating a potential BAC vulnerability. We used Beacon to test eight popular DBMSs (e.g., MySQL and MariaDB), uncovering 39 previously unknown BAC vulnerabilities. Among them, 19 result in privilege escalation, and 20 lead to unauthorized information disclosure.Moreover, 7 of them have existed in DBMSs for more than 6 years, with the longest-persisting one lasting 13 years. DBMS vendors took these issues seriously and have already confirmed all of these vulnerabilities. Many vendors provided positive feedback, recognizing the importance of addressing these vulnerabilities. For instance, OceanBase awarded bounties for reported vulnerabilities, underscoring Beacon's role in improving DBMS access control.

This program is tentative and subject to change.

Tue 6 Oct

Displayed time zone: Pacific Time (US & Canada) change

15:30 - 17:00
Smart Contracts and BlockchainOOPSLA at Junior Ballroom 3&4
Chair(s): Chandrakana Nandi Certora; University of Washington
15:30
18m
Talk
SymGPT: Auditing Smart Contracts via Combining Symbolic Execution with Large Language Models
OOPSLA
Shihao Xia Pennsylvania State University, Mengting He Pennsylvania State University, Shuai Shao University of Connecticut, Tingting Yu University of Connecticut, Yiying Zhang University of California at San Diego, Nobuko Yoshida University of Oxford, Linhai Song Institute of Computing Technology at Chinese Academy of Sciences
DOI
15:48
18m
Talk
When Specifications Meet Reality: Uncovering API Inconsistencies in Ethereum Infrastructure
OOPSLA
Jie Ma Beihang University; Zhongguancun Laboratory, Ningyu He Hong Kong Polytechnic University, Jinwen Xi Zhongguancun Laboratory, Mingzhe Xing Zhongguancun Laboratory, Liangxin Liu Beihang University, luojiushenzi Beijing Institute of Technology; Zhongguancun Laboratory, Xiaopeng Fu Beijing Institute of Technology; Zhongguancun Laboratory, Chiachih Wu Amber Group, Haoyu Wang Huazhong University of Science and Technology, Ying Gao Beihang University; Zhongguancun Laboratory, Yinliang Yue Zhongguancun Laboratory
DOI
16:06
18m
Talk
Verifying Economic Security of Smart Contracts via Unintended Return
OOPSLA
Yi Rong Columbia University, Xupeng Li CertiK, Ronghui Gu Columbia University
DOI
16:24
18m
Talk
Beacon: Detecting Broken Access Control Vulnerabilities in DBMSs via System Catalog Consistency Validation
OOPSLA
Zongrui Peng Tsinghua University, Jingzhou Fu Tsinghua University, Zhiyong Wu Tsinghua University, Jie Liang Beihang University, Xiangdong Huang Tsinghua University, Dalong Shi Aviation Industry Corporation of China, Yu Jiang Tsinghua University
DOI