Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache Polaris - CVE-2026-42811
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to access and modify objects across the configured bucket.
The vulnerability exists due to improper neutralization of special elements in the CEL expression construction in the Google Cloud Storage credential access boundary generation logic when processing crafted namespace or table identifiers. A remote user can supply a crafted namespace or table name to access and modify objects across the configured bucket.
The issued delegated GCS credentials can be broadened beyond the requested table path, allowing access to unrelated prefixes within the same bucket.