Apache Polaris disclosed two high-severity vulnerabilities that can cause the platform to vend overly broad temporary storage credentials, allowing low-privileged users to reach data outside their intended scope. In CVE-2026-42810, Polaris versions before 1.4.1 accept literal * characters in namespace and table names and then reuse them unescaped when building delegated AWS S3 access policies. Because S3 IAM treats * as a wildcard, credentials issued for crafted names such as f*.t1, f*.*, *.*, and foo.* were shown in testing to match other tables’ S3 paths on both AWS S3 and MinIO.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A CVE listing published technical details for CVE-2026-42810, reiterating that crafted wildcard names such as 'f*.t1', 'f*.*', '*.*', and 'foo.*' could broaden delegated S3 credentials in Apache Polaris. It also highlighted a least-privilege scenario where an attacker without permission on the victim table could still access that table's objects via wildcard-crafted tables.
A CVE entry published details for CVE-2026-42809, describing how staged table creation in Apache Polaris could vend delegated storage credentials for attacker-controlled or unvalidated locations before proper validation and reservation. The entry noted low-privilege abuse paths, path override influence, and high-impact CVSS scoring.
A security advisory disclosed CVE-2026-42810 as an important-severity vulnerability in Apache Polaris before version 1.4.1. The flaw stems from accepting literal '*' characters in namespace and table names and reusing them unescaped in temporary S3 access policies, enabling unauthorized cross-table access and integrity impact.
Private testing against Apache Polaris 1.4.0 on MinIO and AWS S3 confirmed that wildcard-bearing namespace or table names could cause delegated S3 credentials to match other tables' storage paths. Observed impact included reading Iceberg metadata, listing another table's exact S3 prefix, and, with write delegation, creating and deleting objects under another table's prefix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.