PT-2026-68455 · Apache · Apache Polaris

·

CVE-2026-64640

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Polaris (affected versions not specified)
Description An authenticated principal with permissions to register tables or views can cause the system to use catalog storage credentials to read a selected Iceberg metadata file before verifying if the file is within allowed storage locations. This occurs when the system fails to consistently validate storage locations during registration. If the underlying credentials have access to objects outside the defined boundary, limited information from those objects may be disclosed. Additionally, the system may accept registration metadata within an allowed location that references storage locations outside the allowed boundary, although this does not trigger a read of the external locations during registration. This issue requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog credentials can access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64640
PYSEC-2026-3623

Affected Products

Apache Polaris