CVE-2026-42811General(apache / polaris)

LOWCVSS 9.4 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead. Apache Polaris builds Google Cloud Storage downscoped credentials by creating a Credential Access Boundary (CAB) with CEL conditions that are intended to restrict access to the requested table's storage path. The relevant CEL string is built from the bucket name and the table path. That table path is derived from namespace and table identifiers. In current code, that path appears to be inserted into the CEL expression without escaping. As a result, a namespace or table identifier containing a single quote and other URI-safe CEL fragments can break out of the intended quoted string and change the meaning of the CEL condition. In private testing against Polaris 1.4.0 on real Google Cloud Storage, it was confirmed that Polaris accepted a crafted identifier and returned delegated GCS credentials whose CEL path restriction had effectively collapsed. Those delegated credentials could then: - list another table's object prefix; - read another table's metadata control file (Iceberg metadata JSON); - create and delete an object under another table's object prefix; - and also list, read, create, and delete objects under an unrelated external prefix in the same bucket that was not part of any table path. That last point is important. The issue is not limited to "another table". In the confirmed setup, once Apache Polaris returned credentials for the crafted table, the path restriction inside the configured bucket was effectively gone. The practical effect is that temporary credentials for one crafted table can be broader than the table Polaris was asked to authorize, and can become effectively bucket-wide within the configured bucket. The current GCS testing used a Polaris principal with broad catalog privileges for setup. A separate least-privilege Polaris RBAC variant has not yet been tested on GCS. However, the storage-credential broadening behavior itself has been confirmed on GCS.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-917

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • polaris

Threat summary

  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • General: 5 classified signals
  • Disclosure: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-13)
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
polaris

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-05-02: 2Mentions · 2026-05-04: 2Mentions · 2026-05-13: 4Technical Details · 2026-05-02: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-13: 305-0205-0405-13
Signal classification2 categories
General
562.5%
Disclosure
337.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-022
Disclosure1General1
2026-05-042
General2
2026-05-134
Disclosure2General2
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-42811 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑42811 as a critical vulnerability with a CVSS score of 9.9, providing its severity metrics but no further details.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42811 (CVSS 9.9) — multiple products. CVE: CVE-2026-42811 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    An advisory lists CVE‑2026‑42811 as a critical vulnerability with a CVSS 3.1 score of 9.9, affecting multiple products; no evidence of PoC, exploitation tools, active use, or patch details is provided.

    1000038
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-42811 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace…

    Post summary

    The excerpt advertises a critical advisory (CVE-2026-42811) for Apache Polaris, describing a credential scoping flaw, but offers no PoC, exploit, patch details, or evidence of active exploitation.

    1000044
    210 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Polaris CVE-2026-42811: Crafted namespace or table name can cause GCS credentials to work across the configured bucket instead of one table's files https://www.openwall.com/lists/oss-security/2026/05/02/12 CVE-2026-42812: Apache Polaris: No protection on write.metadata.path https://www.openwall.com/lists/oss-security/2026/05/02/13

    Post summary

    Apache Polaris has disclosed two new CVEs, detailing how crafted namespace or table names can lead to GCS credentials being used across the entire bucket and the lack of protection on write.metadata.path, but no PoC, exploit code, active exploitation, patches, or debunking statements are included.

    00010263
    4.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42811-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text offers minimal information; it simply references a URL and includes generic hashtags, so no concrete indicators of exploitation, patching, or analysis are discernible.

    0000026
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-42811 In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause … https://www.cve.org/CVERecord?id=CVE-2026-42811 ----- Traducción: CVE-2026-42811 En … http://infoflow.cloud`

    Post summary

    The post cites CVE‑2026‑42811 and notes a credential‑issue flaw in Apache Polaris that can be exploited via crafted namespace or table names, but provides no evidence of PoC, exploitation, or mitigation.

    0000028
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42811 In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause … https://www.cve.org/CVERecord?id=CVE-2026-42811

    Post summary

    The message references CVE-2026-42811 with a brief, incomplete description and a link to the CVE record, but lacks any detailed technical info, exploitation data, or mitigation details.

    00000187
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42811 CVE-2026-42811 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42811

    Post summary

    The post merely references CVE-2026-42811 along with a link, offering no additional information about the vulnerability, its exploitation, or mitigation.

    0000037
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachepolaris---

Explore more