Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-56207: Apache Impala lets attacker pretend to be another user

CVE-2026-56207 · published 1 month ago
Summary

Impala’s web interface does not properly check the signature on SAML authentication tokens, so an attacker can change the user name in the token and act as a different user. This could give the attacker access to data or actions they should not have. Upgrade Impala to version 4.5.2 or later to fix the issue.

What to do
  • Update apache impala to version 4.5.2 or later.
Affected software
VendorProductAffected versions
apache software foundation apache impala <= 4.5.1
apache impala >= 4.0.0, < 4.5.2
cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*
Original advisory text
Apache Impala: SAML authentication bypass via forged bearer token
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user.



This issue affects Apache Impala: >=4.0.0.



Users are recommended to upgrade to version 4.5.2, which fixes this issue.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published9 Sep 2026
Updated7 Oct 2026
First seen9 Sep 2026
Sources
CVE-2026-56207 · MITRE
Track software like this
Free during beta