PT-2026-36671 · Apache · Apache Polaris
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Polaris versions prior to 1.4.1
Description
Changing the
write.metadata.path table property via an ALTER TABLE settings change allows a user to bypass the commit-time branch intended to revalidate storage locations. This defect enables Apache Polaris to write table metadata to an attacker-chosen storage location before location validation occurs. If the catalog is configured with polaris.config.allow.unstructured.table.location=true and the allowedLocations allowlist is broad enough, this can lead to the persistence of the malicious path in the table state. Consequently, table-load and credential APIs may issue temporary cloud-storage credentials for the attacker-specified area, potentially exposing, modifying, or corrupting data and metadata within that storage scope, including other tables or bucket roots.Recommendations
Update to version 1.4.1.
Restrict the ability to change table properties.
Enforce strict storage allowlists within the
allowedLocations configuration.Exploit
Fix
RCE
Incorrect Permission
Improper Access Control
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Polaris