Apache Impala
4 known vulnerabilities in Apache Impala, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-65181 CVSS 8.1 high Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and…
- CVE-2026-57866 CVSS 8.8 high Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permissions to execute the…
- CVE-2026-56207 CVSS 9.8 critical Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user…
- CVE-2026-54048 CVSS 5.3 medium Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms…