PT-2026-36670 · Apache · Apache Polaris

Jean-Baptiste Onofré

·

Published

2026-05-02

·

Updated

2026-05-13

·

CVE-2026-42811

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Polaris version 1.4.0
Description Apache Polaris fails to properly escape namespace and table identifiers when constructing Common Expression Language (CEL) strings for Google Cloud Storage (GCS) Credential Access Boundaries (CAB). This allows a crafted namespace or table name containing single quotes and URI-safe CEL fragments to break out of the intended quoted string and alter the CEL condition. Consequently, short-lived GCS credentials intended for a single table can be broadened to provide bucket-wide access within the configured bucket. This enables unauthorized actions, including listing, reading, creating, and deleting objects under other tables' prefixes or unrelated external prefixes in the same bucket.
Recommendations For version 1.4.0, restrict the use of crafted namespace or table identifiers until a fix is applied.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-42811
GHSA-FC3H-C6H7-R83J

Affected Products

Apache Polaris