


Perceptive Security
SOC/SIEM Consultancy

In Apache Iceberg, the table's metadata files are control files: they tell readers
which data files belong to the table and which table version to read.
`wri…
Published:
3 May 2026 at 22:00:00
Alert date:
4 May 2026 at 18:09:25
Source:
nvd.nist.gov
Database & Storage, Cloud & Virtualization
Apache Iceberg vulnerability where changing the write.metadata.path property through ALTER TABLE bypasses location validation in Polaris-managed catalogs. Attackers can cause Polaris to write metadata to attacker-chosen storage locations, potentially exposing or corrupting data beyond the target table. The issue requires polaris.config.allow.unstructured.table.location=true and broad allowedLocations configuration. Primary defect is that Polaris skips intended location checks when only write.metadata.path changes, leading to unauthorized storage access and credential vending.
Technical details
Mitigation steps:
Affected products:
Apache Iceberg
Apache Polaris
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42812
https://lists.apache.org/thread/wxd2wj3p0smvrk84msv317wg5tp3jtw9
http://www.openwall.com/lists/oss-security/2026/05/02/13
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
