Back to VulnFeed / CVE-2026-42811
root@hackertop:~/vulnfeed/CVE-2026-42811#
CVE-2026-42811 MEDIUM CVE ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

Apache Polaris up to 1.4.0 improper authentication

Polaris 18d ago Impact pending confirmation
LIFECYCLE
6.0 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability was found in Apache Polaris up to 1.4.0. It has been classified as critical. This affects an unknown functionality. Upgrading to version 1.4.1 eliminates this vulnerability.
Root Cause Analysis
CWE is classifying the issue as CWE-287. When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Impact: This is going to have an impact on confidentiality, integrity, and availability.

Countermeasure: Upgrading to version 1.4.1 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-42811 · CVSS 6.0 · Active Threat