Improper Authorization in Apache Polaris - CVE-2026-42812
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and modify or corrupt data in attacker-chosen reachable storage locations.
The vulnerability exists due to improper access control in the write.metadata.path handling logic when changing table settings through an ALTER TABLE-style settings change. A remote user can change the write.metadata.path property to cause Polaris to write metadata to an attacker-chosen storage location and later obtain temporary storage credentials for that location to disclose sensitive information and modify or corrupt data in attacker-chosen reachable storage locations.
The full persisted and credential-vending variant requires the affected catalog to allow unstructured table locations with an allowlist broad enough to include the chosen target. Even when that configuration is not enabled, Polaris still skips the intended pre-write location check for this property change.