CVE-2026-97395
Published 29 September 2026 · tracked since 30 September 2026
Description
Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata.In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use tho
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-71898 MEDIUM 4.3
- CVE-2026-71899
- CVE-2026-78214 MEDIUM 5.3
- CVE-2026-81569 MEDIUM 4.3
- CVE-2026-71897 MEDIUM 4.3
- CVE-2026-98164
- CVE-2026-82804 HIGH 8.8
- CVE-2026-82973 CRITICAL 9.4
- CVE-2026-73599 MEDIUM 5.4
- CVE-2026-100823