CVE-2026-34214
HIGHTrino: Iceberg REST catalog static and vended credentials are accessible via query JSON
Title source: cnaDescription
Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users that have write privilege on SQL level. This issue has been patched in version 480.
Scores
CVSS v3
7.7
EPSS
0.0001
EPSS Percentile
3.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-212
CWE-312
Status
published
Products (3)
io.trino/trino-iceberg
439 - 480Maven
trino/trino
439 - 480
trinodb/trino
>= 439, < 480
Published
Mar 31, 2026
Tracked Since
Mar 31, 2026