{"id":"CVE-2026-97395","published":"2026-09-29T14:17:22.020","lastModified":"2026-09-29T16:17:18.410","description":"Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata.\n\n\nIn versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation.\n\n\n\n\nThis can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread.html/nrk339vtlkpsjw3mg4mqw52j0167wyph","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/29/26","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}