CVE-2026-64640Disclosure(apache / polaris)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside that boundary, this could disclose limited information from the object. Polaris could also accept registration metadata located within an allowed location that contained references to storage locations outside the allowed boundary. This second condition did not itself cause Polaris to read the referenced external locations during registration. The demonstrated impact is limited to confidentiality. No unauthorized data modification or availability impact has been demonstrated. The server-side read requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog's underlying storage credentials can read. Exploitation requires an authenticated principal with table- or view-registration privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • polaris

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
polaris

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-06: 2Technical Details · 2026-08-06: 208-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-64640 Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a … https://www.cve.org/CVERecord?id=CVE-2026-64640 ----- Traducción: CVE-2026-64640 Apa… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-64640 in Apache Polaris, noting that storage location validation during table and view registration is inconsistent, but it provides no PoC, exploit, patch, or active exploitation details.

    0000042
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-64640 Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a … https://www.cve.org/CVERecord?id=CVE-2026-64640

    Post summary

    The text announces CVE‑2026‑64640 in Apache Polaris, explaining that it fails to validate storage locations during table and view registration, potentially enabling authenticated users with registration rights to influence storage paths.

    000001.1K
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachepolaris---

Explore more