Improper Storage Validation in Apache Polaris Affects Data Security
CVE-2026-64640

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 August 2026

What is CVE-2026-64640?

An issue has been identified in Apache Polaris where it fails to consistently validate storage locations during table and view registration. Authenticated users with the necessary permissions can leverage this vulnerability to allow Polaris to access Iceberg metadata files from user-defined locations, potentially exposing sensitive information if the underlying storage credentials permit access to data outside the intended boundaries. The vulnerability presents a risk to confidentiality as it may disclose limited information, although it does not currently allow for unauthorized data modification or affect availability.

Affected Version(s)

Apache Polaris 0 <= 1.6.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrea Cosentino
.