---
id: CVE-2026-97395
title: >-
  Apache Polaris allows an authenticated principal with permission to create or
  update Iceberg table properties to set FileIO client settings such as
  s3.endpoint in table metadata.



  In versions < 1.8.0, when Polaris performs server-side I…
summary: >-
  Apache Polaris allows an authenticated principal with permission to create or
  update Iceberg table properties to set FileIO client settings such as
  s3.endpoint in table metadata.



  In versions < 1.8.0, when Polaris performs server-side I…
severity: none
vendor: Apache Software Foundation
product: Apache Polaris
affected:
  - apache_polaris < 1.8.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T16:17:18.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97395'
references:
  - url: 'https://lists.apache.org/thread.html/nrk339vtlkpsjw3mg4mqw52j0167wyph'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/29/26'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T14:36:14.087Z'
---

## Overview

Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata.


In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation.




This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
