Junglewise Threat Intelligence

CVE-2026-42809: Apache Polaris improper authorization in staged table creation

CVE-2026-42809 · Severity: critical · CVSS 9.9 · Published 2026-05-04

Technologies: Apache Polaris. Vendors: Maven, Apache.

Executive brief

Apache Polaris, a data management service, contains a security flaw that allows users to obtain unauthorized access to cloud storage. By providing a custom storage location during the table creation process, an attacker can trick the system into issuing temporary security credentials for locations they should not be able to access. This could lead to the unauthorized viewing, modification, or deletion of sensitive data stored in the cloud.

Technical details

Apache Polaris is vulnerable to an authorization bypass and improper input validation during the 'staged table creation' workflow. When a user initiates a stage-create request with a custom 'location' and requests credential vending, the application generates delegated storage credentials immediately without performing standard location validation or overlap checks. Attackers can also influence the credential scope via 'write.data.path' and 'write.metadata.path' properties. This allows an authenticated, low-privileged user to mint temporary credentials for any reachable target location they specify. The issue is addressed in Apache Polaris version 1.4.1.

Affected products

  • Apache Polaris before 1.4.1

Timeline

  • 2026-05-02: disclosed: Initial disclosure on oss-security mailing list
  • 2026-05-04: advisory: NVD publication date
  • 2026-05-12: other: NVD analysis and CPE assignment

References

Related threats