Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-97720: Apache Impala lets anyone use its executor web interface

CVE-2026-97720 · published 3 days ago
Summary

The web server used by Impala’s executors can be tricked into accepting any login token, letting an attacker view or interact with the service when token authentication is turned on. Disable JWT/OAuth authentication for the executors or upgrade to Impala 4.5.3, which corrects the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apache software foundation apache impala <= 4.5.2
Original advisory text
Apache Impala: Impala Executor Webserver Auth Bypass
Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens.  Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT.
Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-303Incorrect Implementation of Authentication Algorithm
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-97720 · MITRE
Track software like this
Free during beta