Skip to content
Rota Nacional

Cyber ·

CVE-2026-97395: Apache Polaris FileIO risk

A security feed reports that Apache Polaris versions before 1.8.0 may let FileIO requests be redirected to attacker-controlled endpoints.

The security feed says CVE-2026-97395 affects Apache Polaris versions before 1.8.0. According to its description, an authenticated user allowed to create or update Iceberg table properties can set FileIO client settings, such as s3.endpoint, in table metadata. In affected versions, those settings are used to build the server-side FileIO client, potentially directing requests to attacker-controlled endpoints. The item rates the severity as important.

The post attributes the notice to Jean-Baptiste Onofré and gives the date as September 29, 2026; because that date is in the future at the time of this response, confirm the timeline and details in the original oss-sec notice and official project documentation before acting. Check the installed version and permissions that allow table-property changes. If you use AI to review configurations, remove sensitive organizational data or apply your organization's policy before submitting the content.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free