Apache
Apache Polaris: vulnerabilities and CVEs
Apache Polaris has 6 published vulnerabilities, 6 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months6
Critical4
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97395 | High (8.1) | 0.28% | — | Sep 29, 2026 | Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris… |
| CVE-2026-64640 | Medium (5.3) | 0.49% | — | Aug 6, 2026 | Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release… |
| CVE-2026-42812 | Critical (9.4) | 0.59% | — | May 4, 2026 | In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells… |
| CVE-2026-42811 | Critical (9.4) | 0.72% | — | May 4, 2026 | In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured… |
| CVE-2026-42810 | Critical (9.4) | 0.69% | — | May 4, 2026 | Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM… |
| CVE-2026-42809 | Critical (9.4) | 0.58% | — | May 4, 2026 | Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.