What is CVE-2026-64640?
CVE-2026-64640 is a vulnerability in Apache Polaris where storage locations supplied during table and view registration are not consistently validated. An authenticated principal with registration permissions could exploit this to force the use of the catalog's storage credentials, depending on the release and path. Affected users should apply the relevant patch and review storage location validation policies.
Azərbaycanca: CVE-2026-64640 Apache Polaris-də cədvəl və görünüş qeydiyyatı zamanı təmin edilən storage location-ların ardıcıl yoxlanılmaması zəifliyidir. Authenticated principal öz icazələrindən sui-istifadə edərək kataloqun storage credentials-lərini istifadə etməyə məcbur edə bilər. Polaris istifadəçiləri müvafiq yeniləməni tətbiq etməli və storage location validation qaydalarını nəzərdən keçirməlidir.
Related CVEs
link basis: shared vendor: Apache
FAQ1
How can CVE-2026-64640 be exploited in Apache Polaris?
An authenticated principal with registration permissions can exploit the inconsistent validation of supplied storage locations during table and view registration to force the use of the catalog's storage credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.