Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-97720: Apache Impala lets anyone use its executor web interface
CVE-2026-97720 · published 3 days ago
Summary
The web server used by Impala’s executors can be tricked into accepting any login token, letting an attacker view or interact with the service when token authentication is turned on. Disable JWT/OAuth authentication for the executors or upgrade to Impala 4.5.3, which corrects the problem.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache impala | <= 4.5.2 |
Original advisory text
Apache Impala: Impala Executor Webserver Auth Bypass
Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens. Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT.
Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.
Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-303Incorrect Implementation of Authentication Algorithm
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta