Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Polaris - CVE-2026-42811

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Polaris - CVE-2026-42811

Published: August 25, 2026


Vulnerability identifier: #VU145300
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42811
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access and modify objects across the configured bucket.

The vulnerability exists due to improper neutralization of special elements in the CEL expression construction in the Google Cloud Storage credential access boundary generation logic when processing crafted namespace or table identifiers. A remote user can supply a crafted namespace or table name to access and modify objects across the configured bucket.

The issued delegated GCS credentials can be broadened beyond the requested table path, allowing access to unrelated prefixes within the same bucket.


Affected software

Apache Polaris

How to mitigate CVE-2026-42811

Install security update from vendor's website.

Apache Polaris - update to 1.4.1

External References

Related Security Bulletins