HIGH 8.1 NVD
CVE-2026-65181
Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to exec
Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.
Affected Products
- apache/impala
References
- https://lists.apache.org/thread/2ty3srsh96j86xxg4g1hbo5rwvszwcnl
- http://www.openwall.com/lists/oss-security/2026/09/08/24
- https://www.openwall.com/lists/oss-security/2026/09/08/24
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-09-09 via NVD. Affected: apache/impala.
vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.