CVE-2026-42810Disclosure(apache / polaris)

LOWCVSS 9.4 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions. In S3 IAM policy matching, `*` is treated as a wildcard rather than as ordinary text. That means temporary credentials issued for one crafted table can match the storage path of a different table. In private testing against Polaris 1.4.0 using Polaris' AWS S3 temporary- credential path on both MinIO and real AWS S3, credentials returned for crafted tables such as `f*.t1`, `f*.*`, `*.*`, and `foo.*` could reach other tables' S3 locations. The confirmed behavior includes: - reading another table's metadata control file ([Iceberg metadata JSON]); - listing another table's exact S3 table prefix ([table prefix]); - and, when write delegation was returned for the crafted table, creating and deleting an object under another table's exact S3 table prefix. A control case using ordinary different names did not allow the same cross-table access. A least-privilege AWS S3 variant was also confirmed in which the attacker principal had no Polaris permissions on the victim table and only the minimal permissions required to create and use a crafted wildcard table (namespace-scoped `TABLE_CREATE` and `TABLE_WRITE_DATA` on `*`). In that setup, direct Polaris access to `foo.t1` remained forbidden, but the attacker could still create and load `*.*`, receive delegated S3 credentials, and use those credentials to list, read, create, and delete objects under `foo.t1`. In Iceberg, the metadata JSON file is a control file: it tells readers which data files belong to the table, which snapshots exist, and which table version to read. So unauthorized access to it is already a meaningful confidentiality problem. The confirmed write-capable variant means the issue is not limited to disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • polaris

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-13)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
polaris

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-05-02: 2Mentions · 2026-05-04: 1Mentions · 2026-05-13: 4Technical Details · 2026-05-02: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-13: 305-0205-0405-13
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-022
Disclosure1General1
2026-05-041
Disclosure1
2026-05-134
Disclosure3General1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    4 CVEs in Apache Polaris, all are "important" CVE-2026-42809: An authenticated low-privileged user can mint broad temporary storage credentials https://www.openwall.com/lists/oss-security/2026/05/02/10 CVE-2026-42810: Accepted literal `*` characters reused unescaped in S3 IAM https://www.openwall.com/lists/oss-security/2026/05/02/11 + next tweet

    Post summary

    The text announces two newly identified CVEs in Apache Polaris, providing technical details about the vulnerabilities and linking to advisory discussions. No evidence of PoC, exploit code, active exploitation, or remediation is provided.

    10071563
    4.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42810 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Apache Polaris accepts literal characters in namespace and table names.

    Post summary

    The text announces a critical CVE for Apache Polaris, detailing its high CVSS score and an input validation issue, but it provides no PoC, exploit, patch or evidence of ongoing attacks.

    1000043
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-42810 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    This entry announces CVE-2026-42810, noting its CVSS score of 9.9 and critical severity, without any evidence of PoC, exploit, active use, or patch information.

    1000041
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42810 (CVSS 9.9) — multiple products. CVE: CVE-2026-42810 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a critical advisory for CVE-2026‑42810, highlighting its high CVSS score of 9.9.

    1000034
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42810-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The shared text only references a URL and tags, lacking any specific details about the CVE, its exploitation, or remediation.

    0000023
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42810 Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same c… https://www.cve.org/CVERecord?id=CVE-2026-42810

    Post summary

    The note details Apache Polaris accepting literal `*` characters in names, hinting at S3 policy issues, but offers no PoC, exploit, or mitigation.

    00000124
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42810 CVE-2026-42810 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42810 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The text merely references CVE‑2026‑42810 and provides a link to a vulnerability database without any additional details, PoC, or mitigation information.

    0000052
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachepolaris---

Explore more