Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-56207: Apache Impala lets attacker pretend to be another user
CVE-2026-56207 · published 1 month ago
Summary
Impala’s web interface does not properly check the signature on SAML authentication tokens, so an attacker can change the user name in the token and act as a different user. This could give the attacker access to data or actions they should not have. Upgrade Impala to version 4.5.2 or later to fix the issue.
What to do
- Update apache impala to version 4.5.2 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache impala | <= 4.5.1 |
| apache | impala |
>= 4.0.0, < 4.5.2 cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:* |
Original advisory text
Apache Impala: SAML authentication bypass via forged bearer token
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user.
This issue affects Apache Impala: >=4.0.0.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.
This issue affects Apache Impala: >=4.0.0.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.
References
- https://lists.apache.org/thread/20cov78py0zqzx7dyq39ktythkwn91zs Mailing List Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/09/08/22 Mailing List Third Party Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published9 Sep 2026
Updated7 Oct 2026
First seen9 Sep 2026
Track software like this
Free during beta