Junglewise Threat Intelligence

CVE-2026-42811: Apache Polaris expression injection in GCS credential delegation

CVE-2026-42811 · Severity: critical · CVSS 9.9 · Published 2026-05-04

Technologies: Apache Polaris. Vendors: Maven, Apache.

Executive brief

Apache Polaris, a data management service, contains a flaw in how it handles Google Cloud Storage (GCS) permissions. An attacker can use specially crafted table or namespace names to bypass security restrictions and obtain broad access to an entire storage bucket. This allows unauthorized users to read, modify, or delete sensitive data across the entire bucket, rather than being restricted to a single table.

Technical details

Apache Polaris is vulnerable to an expression language injection in its Google Cloud Storage (GCS) credential delegation mechanism. The service constructs Common Expression Language (CEL) strings for Credential Access Boundaries (CAB) by concatenating bucket names and table paths without proper escaping. An attacker with permissions to create or interact with namespaces/tables can use single quotes and URI-safe CEL fragments to break out of the intended string literal. This 'collapses' the path restriction, granting the attacker delegated credentials with full list, read, and write access to the entire GCS bucket. The vulnerability is confirmed in version 1.4.0 and addressed in 1.4.1.

Affected products

  • Apache Polaris before 1.4.1

Timeline

  • 2026-05-02: disclosed: Initial disclosure on oss-security mailing list
  • 2026-05-04: advisory: NVD publication date
  • 2026-05-04: patched: Fix available in version 1.4.1

References

Related threats