Improper access control in Apache Polaris - CVE-2026-42809
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to obtain broad temporary storage credentials for an attacker-chosen location.
The vulnerability exists due to improper access control in the staged table creation flow when processing a stage-create request with a custom location or location override properties before the location is validated. A remote user can submit a specially crafted stage-create request to obtain broad temporary storage credentials for an attacker-chosen location.
The issue affects credential vending during staged table creation and also involves the use of write.data.path and write.metadata.path as attacker-influenced location inputs.