CVE-2026-97395
Received Received - Intake

Unauthorized Endpoint Redirection in Apache Polaris

Vulnerability report for CVE-2026-97395, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation. This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache polaris to 1.8.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Apache Polaris versions before 1.8.0 allow authenticated users with permission to create or update Iceberg table properties to set FileIO client settings like s3.endpoint in table metadata. This can cause Polaris to send server-side storage requests to a host chosen by the table writer, potentially exposing authentication credentials if the catalog storage configuration does not override the endpoint.

Impact Analysis

If you use Apache Polaris versions before 1.8.0 and allow untrusted users to create or modify Iceberg tables, this vulnerability could let attackers redirect server-side storage requests to malicious endpoints. This may expose sensitive authentication credentials used by Polaris for storage operations.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by exposing request authentication material to unauthorized endpoints. Untrusted table writers could redirect server-side storage traffic, leading to unauthorized access to sensitive data during Iceberg operations.

Mitigation Strategies

Upgrade Apache Polaris to version 1.8.0 or later to address the vulnerability in FileIO client settings handling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97395. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart