CVE-2026-42812

critical
Published 2026-05-04 · Modified 2026-05-08
CVSS v3
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v2
VIR risk
9.9

Description

Apache Polaris has an Improper Input Validation issue

Predictions

Exploit likelihood
98%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — https://lists.apache.org/thread/wxd2wj3p0smvrk84msv317wg5tp3jtw9

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.polaris:polaris-runtime-service<1.4.11.4.1
java MAVENorg.apache.polaris:polaris-runtime-service< 1.4.11.4.1

Application impact

VendorProductVersionsFixed
apache apachepolaris{"endExcluding":"1.4.1"}1.4.1

References

CWEs

CWE-20 CWE-284 CWE-732 CWE-863

Verify integrity in audit chain (admin only). AS-IS.