Skip to main content
Mallory
Back to intelligence
cloud-service-vulnerabilityidentity-authentication-vulnerabilitywidely-deployed-product-advisorydata-exfiltration-method

Apache Polaris flaws let low-privileged users mint bucket-wide GCS credentials

Updated 24d agoFirst seen May 2, 20263 sources

Apache disclosed two important-severity vulnerabilities in Apache Polaris fixed in version 1.4.1 that can let an authenticated low-privileged user obtain overly broad temporary Google Cloud Storage credentials. In CVE-2026-42809, Polaris can vend delegated storage credentials during staged table creation before validating or reserving the requested location, allowing an attacker to supply a custom location and receive access for an attacker-chosen path. The staged-create flow also accepts write.data.path and write.metadata.path properties that can further influence the effective table location used for credential vending.

In CVE-2026-42811, Polaris incorrectly builds Credential Access Boundary CEL conditions for downscoped GCS credentials by inserting namespace and table-derived paths without escaping. Apache said a crafted namespace or table identifier can break out of the intended quoted string and collapse the path restriction, causing credentials meant for one table to work across the configured bucket. Private testing against Polaris 1.4.0 on real GCS showed the returned credentials could list, read, create, and delete objects under other table prefixes and unrelated external prefixes in the same bucket, making the practical impact effectively bucket-wide access within that bucket.

Share:
Apache Polaris flaws let low-privileged users mint bucket-wide GCS credentials
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 2, 202627d ago

Private testing confirms bucket-wide GCS access via CVE-2026-42811

Testing against Polaris 1.4.0 on real Google Cloud Storage confirmed that a crafted identifier could collapse path restrictions in delegated credentials. The returned credentials allowed listing, reading, creating, and deleting objects under other table prefixes and unrelated external prefixes in the same bucket.

Apache discloses CVE-2026-42811 affecting Polaris GCS credential scoping

Apache disclosed CVE-2026-42811, an important-severity vulnerability in Apache Polaris before version 1.4.1 involving Google Cloud Storage downscoped credentials. Crafted namespace or table identifiers could break the intended CEL-based restriction and broaden temporary credentials to effectively bucket-wide access within the configured bucket.

Apache discloses CVE-2026-42809 in Polaris staged table creation

Apache disclosed CVE-2026-42809, an important-severity flaw in Apache Polaris before version 1.4.1. An authenticated low-privileged user could abuse staged table creation to obtain broad temporary storage credentials for an attacker-chosen location before Polaris validates or reserves it.

Apache fixes Polaris credential-vending flaws in version 1.4.1

Apache states that vulnerabilities affecting Apache Polaris versions before 1.4.1 were fixed in release 1.4.1. The fixes address improper temporary storage credential scoping issues, including staged table creation abuse and GCS access-boundary manipulation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.