← All Advisories

CVE-2026-97395

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97395

Key Details

CVECVE-2026-97395
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsApache Software Foundation Apache Polaris
Classified asCWE-862 (Missing Authorization)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apache Software FoundationApache Polaris
SubsystemsGeneral OT
SectorsMultiple

What to Know

Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata.

In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation.

This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints. (NVD)

What to Do

Monitor Apache Software Foundation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97395
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97395