Known vulnerabilities in Apache Polaris 1.4.0
Vendor:
Apache Foundation
Software:
Apache Polaris
Version:
1.4.0
Software CPE:
cpe:2.3:a:apache_foundation:apache_polaris:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Vulnerabilities by Severity
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU145301 - Improper Authorization CVE-2026-42812 |
CWE-285 | Medium | 1.4.1 | 25.08.2026 |
SB2026082599 |
||
| #VU145300 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CVE-2026-42811 |
CWE-74 | Medium | 1.4.1 | 25.08.2026 |
SB2026082599 |
||
| #VU145299 - Improper Neutralization of Wildcards or Matching Symbols CVE-2026-42810 |
CWE-155 | Medium | 1.4.1 | 25.08.2026 |
SB2026082599 |
||
| #VU145298 - Improper Access Control CVE-2026-42809 |
CWE-284 | Low | 1.4.1 | 25.08.2026 |
SB2026082599 |
||
| #VU145157 - Improper Authorization CVE-2026-64640 |
CWE-285 | Low | 1.7.0 | 25.08.2026 |
SB2026082551 |