« Back to list

Apache

Apache Polaris: vulnerabilities and CVEs

Apache Polaris has 6 published vulnerabilities, 6 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months6
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-97395High (8.1)0.28%—Sep 29, 2026
Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris…
CVE-2026-64640Medium (5.3)0.49%—Aug 6, 2026
Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release…
CVE-2026-42812Critical (9.4)0.59%—May 4, 2026
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells…
CVE-2026-42811Critical (9.4)0.72%—May 4, 2026
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured…
CVE-2026-42810Critical (9.4)0.69%—May 4, 2026
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM…
CVE-2026-42809Critical (9.4)0.58%—May 4, 2026
Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services5
  2. T1005 Data from Local System1
  3. T1078 Valid Accounts1
  4. T1078.004 Cloud Accounts1
  5. T1552.007 Container API1
  6. T1565.001 Stored Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Apache