CVE-2026-97395: Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints using operation-scoped storage credentials

Published Sep 29, 2026
·
Updated

Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata.

In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation.

This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints.

Affected Software

1 affected component
Apache Polaris<1.8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Polaris to a version that resolves this vulnerability.

    Fixed in 1.8.0
  2. Configuration

    Configure the catalog storage configuration to override the endpoint so table writers cannot redirect server-side Iceberg FileIO requests.

    Apache Polaris catalog storage configuration storage endpoint override = override the table-provided endpoint

Event History

Sep 29, 2026
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
Description
Data Sourced
via NVD·02:17 PM
Description

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments are affected when authenticated users who can create or update Iceberg table properties are not trusted to configure server-side storage endpoints. The catalog storage configuration must also not override the endpoint selected through table metadata.

2

What level of access does an attacker need?

An attacker needs to be an authenticated principal with permission to create or update Iceberg table properties. They can set FileIO client settings, such as s3.endpoint, in table metadata.

3

What can the attacker redirect, and what could be exposed?

During server-side Iceberg operations such as commits and purges, Polaris may send storage requests to an attacker-controlled host. Those requests can include authentication material from credentials scoped to the operation.

4

Are deployments protected if the catalog storage configuration sets an endpoint?

The described redirection occurs when the catalog storage configuration does not override the endpoint. Configuring the catalog to override the endpoint prevents table metadata from selecting the endpoint used for these server-side storage requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203