CVE-2026-42809General(apache / polaris)

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache polaris systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data and metadata, but this scope limitation becomes attacker- directed because the attacker can choose a reachable target location. In the confirmed variant, if the caller supplies a custom `location` during stage create and requests credential vending, Apache Polaris uses that location to construct delegated storage credentials immediately. The stage-create path itself neither runs the normal location validation nor the overlap checks before those credentials are issued. Closely related to that, the staged-create flow also accepts `write.data.path` / `write.metadata.path` in the request properties and feeds those location overrides into the same effective table location set used for credential vending. Those fields are secondary to the main custom-`location` exploit, but they are still attacker-influenced location inputs that should be validated before any credentials are issued.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • polaris

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-02); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
polaris

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-05-02: 2Mentions · 2026-05-04: 2Mentions · 2026-05-13: 2Mentions · 2026-06-13: 1Mentions · 2026-08-24: 1Patch / Workaround · 2026-08-24: 1Technical Details · 2026-05-02: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-13: 1Technical Details · 2026-06-13: 105-0205-0405-1306-1308-24
Signal classification3 categories
General
450.0%
Disclosure
337.5%
Patch
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-022
Disclosure1General1
2026-05-042
Disclosure2
2026-05-132
General2
2026-06-131
General1
2026-08-241
Patch1
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    4 CVEs in Apache Polaris, all are "important" CVE-2026-42809: An authenticated low-privileged user can mint broad temporary storage credentials https://www.openwall.com/lists/oss-security/2026/05/02/10 CVE-2026-42810: Accepted literal `*` characters reused unescaped in S3 IAM https://www.openwall.com/lists/oss-security/2026/05/02/11 + next tweet

    Post summary

    The tweet lists four important CVEs in Apache Polaris, providing brief technical details and linking to security mailing‑list discussions, but does not mention PoCs, exploitation, patches, or false‑positive claims.

    10071563
    4.7K followersView on X
  • okumin@okumin
    Patch

    Credential Vendingはとんでもない脆弱性を簡単に仕込めてしまうのが怖い。 https://polaris.apache.org/community/security-advisories/cve-2026-42809/ HiveはまだCVリリースしてなかったからすっとガード入れて回避 https://github.com/apache/hive/pull/6641

    Post summary

    The post notes a serious vulnerability in Credential Vending and describes adding a guard in Hive before a formal patch was released.

    00020181
    3.1K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-42809 · 9.9 → 1.4.0 The Data Lake Is Poisoned: Apache Polaris Triple CVSS-9.9 Cluster Exposes Enterprise Lakehouses to Credential Hijack and Arbitrary Storage Access

    Post summary

    The excerpt highlights a high-severity CVE (9.9) affecting Apache Polaris, enabling credential hijack and arbitrary storage access, without indicating PoC availability or ongoing exploitation.

    1000030
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42809 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text lists a CVE with its severity and CVSS details but does not mention PoC, exploits, active attacks, or patches.

    1000042
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42809 Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably… https://www.cve.org/CVERecord?id=CVE-2026-42809

    Post summary

    The post provides a technical overview of CVE-2026-42809, noting how Apache Polaris can issue temporary storage credentials prematurely, but does not mention proof of concept, exploitation, or patches.

    00010178
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42809-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    Only a URL and generic tags are provided; no substantive information about the CVE is conveyed.

    0000025
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42809 Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably… https://www.cve.org/CVERecord?id=CVE-2026-42809 ----- Traducción: CVE-2026-42809 Apa… http://infoflow.cloud`

    Post summary

    The text is a brief disclosure of CVE‑2026‑42809, describing how Apache Polaris may issue broad temporary credentials before validation, with no PoC, exploit, or patch information provided.

    0000036
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42809 CVE-2026-42809 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42809

    Post summary

    The text only references CVE‑2026‑42809 and a vulnerability details link, offering no further information or actionable insights.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachepolaris---

Explore more