PT-2026-36671 · Apache · Apache Polaris

·

CVE-2026-42812

·

Published

2026-05-02

·

Updated

2026-05-13

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Polaris versions prior to 1.4.1
Description Changing the write.metadata.path table property via an ALTER TABLE settings change allows a user to bypass the commit-time branch intended to revalidate storage locations. This defect enables Apache Polaris to write table metadata to an attacker-chosen storage location before location validation occurs. If the catalog is configured with polaris.config.allow.unstructured.table.location=true and the allowedLocations allowlist is broad enough, this can lead to the persistence of the malicious path in the table state. Consequently, table-load and credential APIs may issue temporary cloud-storage credentials for the attacker-specified area, potentially exposing, modifying, or corrupting data and metadata within that storage scope, including other tables or bucket roots.
Recommendations Update to version 1.4.1. Restrict the ability to change table properties. Enforce strict storage allowlists within the allowedLocations configuration.

Exploit

Fix

RCE

Incorrect Permission

Improper Access Control

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42812
GHSA-W76P-3CGP-QFCM

Affected Products

Apache Polaris