Improper Storage Validation in Apache Polaris Affects Data Security
CVE-2026-64640
Key Information:
- Vendor
Apache
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-64640?
An issue has been identified in Apache Polaris where it fails to consistently validate storage locations during table and view registration. Authenticated users with the necessary permissions can leverage this vulnerability to allow Polaris to access Iceberg metadata files from user-defined locations, potentially exposing sensitive information if the underlying storage credentials permit access to data outside the intended boundaries. The vulnerability presents a risk to confidentiality as it may disclose limited information, although it does not currently allow for unauthorized data modification or affect availability.
Affected Version(s)
Apache Polaris 0 <= 1.6.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved