CVE-2026-64640

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
06/08/2026
Last modified:
06/08/2026

Description

Apache Polaris did not consistently validate storage locations supplied during table and view registration.<br /> <br /> An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog&amp;#39;s storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog&amp;#39;s allowed storage locations.<br /> <br /> If the catalog&amp;#39;s underlying credentials could read an object outside that boundary, this could disclose limited information from the object.<br /> <br /> <br /> Polaris could also accept registration metadata located within an allowed location that contained references to storage locations outside the allowed boundary.<br /> <br /> This second condition did not itself cause Polaris to read the referenced external locations during registration.<br /> <br /> <br /> The demonstrated impact is limited to confidentiality.<br /> <br /> No unauthorized data modification or availability impact has been demonstrated.<br /> <br /> <br /> The server-side read requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog&amp;#39;s underlying storage credentials can read.<br /> <br /> Exploitation requires an authenticated principal with table- or view-registration privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:polaris:*:*:*:*:*:*:*:* 1.6.0 (including)