CRITICAL 9.8 NVD

CVE-2026-56207

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as anothe

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Affected Products

References

Published: 2026-09-09 · Source: NVD · Feed updated: 2026-09-12
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-09 via NVD. Affected: apache/impala.

Risk Timeline

CVE Disclosed2026-09-09 · 2 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-41871Missing Authorization, Use of Externally-Controlled Input to Select Classes or CCRITICAL9.8
CVE-2026-41869Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerabiCRITICAL9.1
CVE-2026-84939Path traversal vulnerability in Apache FreeMarker template loading mechanism, ifCRITICAL9.1
CVE-2026-41870Missing Authorization, Improper Control of Generation of Code ('Code Injection')HIGH8.8
CVE-2026-57866Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  AuthentiHIGH8.8
CVE-2026-65181Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a clieHIGH8.1
vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.