PT-2026-36670 · Apache · Apache Polaris
Jean-Baptiste Onofré
·
Published
2026-05-02
·
Updated
2026-05-13
·
CVE-2026-42811
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Polaris version 1.4.0
Description
Apache Polaris fails to properly escape namespace and table identifiers when constructing Common Expression Language (CEL) strings for Google Cloud Storage (GCS) Credential Access Boundaries (CAB). This allows a crafted namespace or table name containing single quotes and URI-safe CEL fragments to break out of the intended quoted string and alter the CEL condition. Consequently, short-lived GCS credentials intended for a single table can be broadened to provide bucket-wide access within the configured bucket. This enables unauthorized actions, including listing, reading, creating, and deleting objects under other tables' prefixes or unrelated external prefixes in the same bucket.
Recommendations
For version 1.4.0, restrict the use of crafted namespace or table identifiers until a fix is applied.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Polaris