Improper Authorization in Apache Polaris - CVE-2026-42812

 

Improper Authorization in Apache Polaris - CVE-2026-42812

Published: August 25, 2026


Vulnerability identifier: #VU145301
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42812
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify or corrupt data in attacker-chosen reachable storage locations.

The vulnerability exists due to improper access control in the write.metadata.path handling logic when changing table settings through an ALTER TABLE-style settings change. A remote user can change the write.metadata.path property to cause Polaris to write metadata to an attacker-chosen storage location and later obtain temporary storage credentials for that location to disclose sensitive information and modify or corrupt data in attacker-chosen reachable storage locations.

The full persisted and credential-vending variant requires the affected catalog to allow unstructured table locations with an allowlist broad enough to include the chosen target. Even when that configuration is not enabled, Polaris still skips the intended pre-write location check for this property change.


Affected software

Apache Polaris

How to mitigate CVE-2026-42812

Install security update from vendor's website.

Apache Polaris - update to 1.4.1

External References

Related Security Bulletins