Polaris
Vendor:
First CVE: May 4, 2026 · Active for under a year
4
Total CVEs
More Total CVEs than 72% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
9.9
Avg CVSS
Higher Avg CVSS than 99% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Polaris over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 4, 2026
2 months ago
Most Recent CVE
May 4, 2026
81 days ago
CVE Severity & Scoring
Polaris4 CVEs
100%
All CVEs352,294 CVEs
45%
40%
11%
Critical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42811CRITICAL In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
that
only work for one table's files, but a crafted namespace or table name can
cause those credenti | May 4, 2026 | 9.9 | 39 | NO | NO |
CVE-2026-42812CRITICAL In Apache Iceberg, the table's metadata files are control files: they tell readers
which data files belong to the table and which table version to read.
`write.metadata.path` is | May 4, 2026 | 9.9 | 38 | NO | NO |
CVE-2026-42810CRITICAL Apache Polaris accepts literal `*` characters in namespace and table names. When it
later builds temporary S3 access policies for delegated table access, those
same characters appe | May 4, 2026 | 9.9 | 38 | NO | NO |
CVE-2026-42809CRITICAL Apache Polaris can issue broad temporary ("vended") storage credentials during
staged
table creation before the effective table location has been validated or
durably reserved.
Th | May 4, 2026 | 9.9 | 38 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Polaris
Top CWEs
Versions
No cataloged versions.