CVE-2026-34214

Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users that have write privilege on SQL level. This issue has been patched in version 480.
Configurations

Configuration 1 (hide)

cpe:2.3:a:trino:trino:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) Trino es un motor de consulta SQL distribuido para análisis de big data. Desde la versión 439 hasta antes de la versión 480, las credenciales estáticas (clave de acceso) o las credenciales vendidas (clave de acceso temporal) del catálogo REST del conector Iceberg son accesibles para los usuarios que tienen privilegios de escritura a nivel de SQL. Este problema ha sido parcheado en la versión 480.

06 Apr 2026, 16:53

Type Values Removed Values Added
References () https://github.com/trinodb/trino/releases/tag/480 - () https://github.com/trinodb/trino/releases/tag/480 - Release Notes
References () https://github.com/trinodb/trino/security/advisories/GHSA-x27p-5f68-m644 - () https://github.com/trinodb/trino/security/advisories/GHSA-x27p-5f68-m644 - Vendor Advisory
CPE cpe:2.3:a:trino:trino:*:*:*:*:*:*:*:*
First Time Trino trino
Trino

31 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 15:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-34214

Mitre link : CVE-2026-34214

CVE.ORG link : CVE-2026-34214


JSON object : View

Products Affected

trino

  • trino
CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

CWE-312

Cleartext Storage of Sensitive Information