Credential Exposure in Trino Distributed SQL Query Engine
CVE-2026-34214

7.7HIGH

Key Information:

Vendor

Trinodb

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34214?

The Trino distributed SQL query engine, designed for big data analytics, has a vulnerability that exposes static or temporary credentials through the Iceberg connector. Users with write privileges at the SQL level could access these credentials, leading to significant security risks. This issue has been resolved in version 480 of Trino, emphasizing the need for users operating earlier versions to upgrade promptly to protect sensitive data.

Affected Version(s)

trino >= 439, < 480

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.