SB2026082599 - Multiple vulnerabilities in Apache Polaris



SB2026082599 - Multiple vulnerabilities in Apache Polaris

Published: August 25, 2026

Security Bulletin ID SB2026082599
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 75% Low 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-42809)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to obtain broad temporary storage credentials for an attacker-chosen location.

The vulnerability exists due to improper access control in the staged table creation flow when processing a stage-create request with a custom location or location override properties before the location is validated. A remote user can submit a specially crafted stage-create request to obtain broad temporary storage credentials for an attacker-chosen location.

The issue affects credential vending during staged table creation and also involves the use of write.data.path and write.metadata.path as attacker-influenced location inputs.


2) Improper neutralization of wildcards or matching symbols (CVE-ID: CVE-2026-42810)

CWE-ID: CWE-155 - Improper Neutralization of Wildcards or Matching Symbols

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access other tables' S3 objects and modify data across table boundaries.

The vulnerability exists due to improper neutralization of special elements in S3 IAM resource patterns and s3:prefix conditions in the AWS S3 temporary-credential delegation feature when building temporary access policies from namespace and table names containing literal wildcard characters. A remote user can create and use a crafted table name containing `*` characters to access other tables' S3 objects and modify data across table boundaries.

This issue affects delegated table access through temporary S3 credentials and was confirmed for both read access to another table's metadata control file and, when write delegation is returned, object creation and deletion under another table's S3 prefix.


3) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-42811)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access and modify objects across the configured bucket.

The vulnerability exists due to improper neutralization of special elements in the CEL expression construction in the Google Cloud Storage credential access boundary generation logic when processing crafted namespace or table identifiers. A remote user can supply a crafted namespace or table name to access and modify objects across the configured bucket.

The issued delegated GCS credentials can be broadened beyond the requested table path, allowing access to unrelated prefixes within the same bucket.


4) Improper Authorization (CVE-ID: CVE-2026-42812)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information and modify or corrupt data in attacker-chosen reachable storage locations.

The vulnerability exists due to improper access control in the write.metadata.path handling logic when changing table settings through an ALTER TABLE-style settings change. A remote user can change the write.metadata.path property to cause Polaris to write metadata to an attacker-chosen storage location and later obtain temporary storage credentials for that location to disclose sensitive information and modify or corrupt data in attacker-chosen reachable storage locations.

The full persisted and credential-vending variant requires the affected catalog to allow unstructured table locations with an allowlist broad enough to include the chosen target. Even when that configuration is not enabled, Polaris still skips the intended pre-write location check for this property change.


Remediation

Install update from vendor's website.