CVE-2026-64640 is a low-severity vulnerability in Apache Polaris affecting org.apache.polaris:polaris-runtime-service through version 1.6.0. Apache Polaris did not consistently validate storage locations supplied during table and view registration. In affected registration paths, an authenticated principal with permission to register a table or view could cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file resided within the catalog's allowed storage locations. If the catalog's underlying credentials were able to read an object outside that boundary, limited information from that object could be disclosed. Polaris could also accept registration metadata located within an allowed location that referenced storage locations outside the allowed boundary, although that second condition did not itself cause Polaris to read those external locations during registration.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Bash/Docker reproducer for CVE-2026-64640 in Apache Polaris. The main entry point is exploit.sh, supported by scripts/lib.sh and scripts/version-matrix.sh, with docker-compose.yml building a local lab consisting of Apache Polaris plus RustFS S3-compatible storage. The repo also includes documentation, sample evidence from runs against Polaris 1.4.1/1.6.0/1.7.0, synthetic victim metadata objects, and two backport patches. Core exploit capability: a low-privilege authenticated Polaris principal with only catalog content-management/create capability can submit attacker-controlled metadata-location values to the Iceberg REST register endpoints. On vulnerable versions, Polaris vends storage credentials and reads/parses the referenced S3 object before validating the path against allowedLocations. This creates a confused-deputy/server-side read primitive against any object reachable by the catalog’s backing storage credentials. The exploit demonstrates: (1) reflection of canary strings and parsed metadata fields from out-of-scope Iceberg metadata, (2) an oracle that distinguishes existing metadata, missing keys, missing buckets, and non-metadata objects, and (3) the version split where register is vulnerable through <=1.5.0, register is fixed in 1.6.0, but register-view is newly vulnerable in 1.6.0 until fixed in 1.7.0. Repository structure: exploit.sh orchestrates environment startup, authentication, namespace creation, control tests, vulnerable probes, evidence capture, and verdict logic. docker-compose.yml provisions RustFS on ports 9000/9001, seeds in-scope and out-of-scope buckets/objects, starts Polaris on ports 8181/8182, and creates a low-privilege principal with CATALOG_MANAGE_CONTENT. scripts/version-matrix.sh automates testing across multiple Polaris versions. docs/ contains affected-version analysis and remediation guidance. patches/ contains minimal source patches adding pre-validation before credential vending. evidence/ contains captured HTTP responses proving vulnerable and fixed behaviors. victim-data/ contains fabricated Iceberg metadata and a synthetic secret file used as probe targets. This is a real exploit/reproducer rather than a mere detector: it actively drives the vulnerable API paths and demonstrates unauthorized server-side reads and metadata disclosure/oracle behavior, though it does not provide arbitrary code execution or full object exfiltration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.