CVE-2026-42809: Apache Polaris: staged table creation could vend storage credentials for unvalidated locations

Published May 2, 2026
·
Updated

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data and metadata, but this scope limitation becomes attacker- directed because the attacker can choose a reachable target location.

In the confirmed variant, if the caller supplies a custom location during stage create and requests credential vending, Apache Polaris uses that location to construct delegated storage credentials immediately. The stage-create path itself neither runs the normal location validation nor the overlap checks before those credentials are issued.

Closely related to that, the staged-create flow also accepts write.data.path / write.metadata.path in the request properties and feeds those location overrides into the same effective table location set used for credential vending. Those fields are secondary to the main custom-location exploit, but they are still attacker-influenced location inputs that should be validated before any credentials are issued.

Affected Software

2 affected components
Apache Polaris
Apache Polaris<1.4.1

Event History

May 4, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-42809?

CVE-2026-42809 is classified as a moderate severity vulnerability due to its potential to expose storage credentials.

2

How do I fix CVE-2026-42809?

To fix CVE-2026-42809, ensure that storage locations are properly validated and reserved before issuing temporary credentials.

3

What products are affected by CVE-2026-42809?

CVE-2026-42809 affects Apache Polaris.

4

What are the risks associated with CVE-2026-42809?

The main risk of CVE-2026-42809 is unauthorized access to storage credentials if locations are unvalidated.

5

Is there a patch available for CVE-2026-42809?

Check for updates from the Apache Polaris project to find out if a patch or mitigation for CVE-2026-42809 has been released.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203