AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-64640

MEDIUM · CVSS 6.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache Polaris is vulnerable due to inadequate validation of storage locations during table and view registration, allowing authenticated users with the appropriate privileges to potentially access Iceberg metadata files outside designated boundaries. This could lead to unauthorized disclosure of limited information, although there is no risk of data modification or availability issues. Organizations using Apache Polaris, particularly those leveraging S3 credential vending, should prioritize addressing this vulnerability to safeguard sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-64640
Severity
MEDIUM
CVSS
6.5
EPSS
0.36%
Apache

Original NVD Description

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside that boundary, this could disclose limited information from the object. Polaris could also accept registration metadata located within an allowed location that contained references to storage locations outside the allowed boundary. This second condition did not itself cause Polaris to read the referenced external locations during registration. The demonstrated impact is limited to confidentiality. No unauthorized data modification or availability impact has been demonstrated. The server-side read requires a deployment using S3 credential vending and an object outside the allowed locations that the catalog's underlying storage credentials can read. Exploitation requires an authenticated principal with table- or view-registration privileges.

Related CVEs

Other vulnerabilities affecting the same vendor(s)