Improper neutralization of wildcards or matching symbols in Apache Polaris - CVE-2026-42810
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to access other tables' S3 objects and modify data across table boundaries.
The vulnerability exists due to improper neutralization of special elements in S3 IAM resource patterns and s3:prefix conditions in the AWS S3 temporary-credential delegation feature when building temporary access policies from namespace and table names containing literal wildcard characters. A remote user can create and use a crafted table name containing `*` characters to access other tables' S3 objects and modify data across table boundaries.
This issue affects delegated table access through temporary S3 credentials and was confirmed for both read access to another table's metadata control file and, when write delegation is returned, object creation and deletion under another table's S3 prefix.