CVE-2026-42812General(apache / polaris)

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache polaris systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells Polaris where to write those metadata files. For a table already registered in a Polaris-managed catalog, changing only that property through an `ALTER TABLE`-style settings change (not a row-level `INSERT`, `SELECT`, `UPDATE`, or `DELETE`) bypasses the commit-time branch that is supposed to revalidate storage locations. The full persisted / credential-vending variant requires the affected catalog to have `polaris.config.allow.unstructured.table.location=true`, with `allowedLocations` broad enough to include the attacker-chosen target. `allowedLocations` is the admin-configured allowlist of storage paths that the catalog is allowed to use. Public project materials suggest that this flag is a real supported compatibility / layout mode, not just a contrived lab-only prerequisite. In that configuration, a user who can change table settings can cause Apache Polaris itself to write new table metadata to an attacker-chosen reachable storage location before the intended location-validation branch runs. If the later concrete-path validation also accepts that location, Polaris persists the resulting metadata path into stored table state. Later table-load and credential APIs can then return temporary cloud-storage credentials for the same location without revalidating it. In plain terms, Polaris can later hand out temporary storage access for the same attacker-chosen area. That attacker-chosen area does not need to be limited to the poisoned table's own files. If it is a broader storage prefix, another table's prefix, or, depending on configuration or provider behavior, even a bucket/container root, the resulting disclosure or corruption scope can extend to any data and metadata Polaris can reach there. The practical consequences are therefore similar to the staged-create credential-vending issue already discussed: data and metadata reachable in that storage scope can be exposed and, if write-capable credentials are later issued, modified, corrupted, or removed. Even before that later credential step, Polaris itself performs the metadata write to the unchecked location. So the core issue is not only later credential vending. The primary defect is that Polaris skips its intended location checks before performing a security- sensitive metadata write when only `write.metadata.path` changes. When `polaris.config.allow.unstructured.table.location=false`, current code review suggests the later `updateTableLike(...)` validation usually rejects out-of-tree metadata locations before the unsafe path is persisted. That may reduce the persisted / credential-vending variant, but it does not prevent the underlying defect: Polaris still skips the intended pre-write location check when only `write.metadata.path` changes.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-284CWE-732CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • polaris

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-04); latest day: 2
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
polaris

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-05-02: 2Mentions · 2026-05-04: 3Mentions · 2026-05-13: 2Patch / Workaround · 2026-05-04: 1Technical Details · 2026-05-02: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-13: 105-0205-0405-13
Signal classification2 categories
General
457.1%
Disclosure
342.9%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-022
Disclosure1General1
2026-05-043
Disclosure2General1
2026-05-132
General2
Full discourse7 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 apache polaris metadata path validation bypass (CVE-2026-42812) Changing write.metadata.path via ALTER TABLE bypasses Polaris location revalidation, allowing metadata writes to attacker-controlled storage before validation occurs. This can lead to data exposure, credential leakage, and possible corruption depending on configuration and allowed locations. 👉 Affected: Apache Polaris < 1.4.1 | Mitigate by restricting table property changes and enforcing strict storage allowlists

    Post summary

    CVE‑2026‑42812 is a path validation bypass in Apache Polaris <1.4.1 that can expose data and credentials; mitigation involves restricting table property changes and applying strict storage allowlists.

    0101076
    122 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42812 CVSS: 9.9 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The tweet lists a critical CVE with CVSS details but offers no evidence of exploitation, PoC, or mitigation.

    1000040
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.met… https://www.cve.org/CVERecord?id=CVE-2026-42812

    Post summary

    The text provides a brief technical description of CVE‑2026‑42812, explaining how metadata files serve as control files in Apache Iceberg, without mentioning PoC, exploitation, or patches.

    00010178
    57.4K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Polaris CVE-2026-42811: Crafted namespace or table name can cause GCS credentials to work across the configured bucket instead of one table's files https://www.openwall.com/lists/oss-security/2026/05/02/12 CVE-2026-42812: Apache Polaris: No protection on write.metadata.path https://www.openwall.com/lists/oss-security/2026/05/02/13

    Post summary

    The message provides specific technical details of two CVEs in Apache Polaris, describing how crafted inputs lead to credential misuse and lack of protection for write metadata, but does not mention patches, PoCs, or active exploitation.

    00010263
    4.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42812-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    A link to an advisory is shared, but the content offers no actionable details or context about the CVE.

    0000026
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.met… https://www.cve.org/CVERecord?id=CVE-2026-42812 ----- Traducción: CVE-2026-42812 En Ap… http://infoflow.cloud`

    Post summary

    The post provides a brief mention of CVE‑2026‑42812 in Apache Iceberg and cites a CVE record, but it lacks specific technical details, exploit information, or mitigation guidance.

    0000031
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42812 CVE-2026-42812 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42812

    Post summary

    The content merely repeats CVE-2026-42812 and links to a general Vulnerability details page, without offering any exploit, patch, or technical details.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachepolaris---

Explore more