Improper Storage Validation in Apache Polaris Affects Data Security
CVE-2026-64640
5.3MEDIUM
What is CVE-2026-64640?
An issue has been identified in Apache Polaris where it fails to consistently validate storage locations during table and view registration. Authenticated users with the necessary permissions can leverage this vulnerability to allow Polaris to access Iceberg metadata files from user-defined locations, potentially exposing sensitive information if the underlying storage credentials permit access to data outside the intended boundaries. The vulnerability presents a risk to confidentiality as it may disclose limited information, although it does not currently allow for unauthorized data modification or affect availability.
Affected Version(s)
Apache Polaris 0 <= 1.6.0