CVE-2026-90466: Apache Impala: Path traversal executes JARs outside trusted paths
Apache Impala 4.5.2 path traversal can load attacker-controlled JARs outside trusted_jar_paths.
Apache disclosed CVE-2026-90466, rated important, in Apache Impala 4.5.2 before 4.5.3. Path traversal of trusted_jar_paths lets a relative path whose prefix matches a configured trusted URI load an attacker-controlled JAR. The startup flag references URIs for files on local or remote filesystems. The oss-security post does not report active exploitation.
- Affects Apache Impala 4.5.2 before 4.5.3.
- Relative paths can match a trusted_jar_paths prefix.
- An attacker-controlled JAR may load from local or remote filesystems.
- Apache rated the flaw important; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-904666.5—Path traversal loads untrusted JARs in Apache Impalapublished · Apache Impala
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-90466 | Path traversal loads untrusted JARs in Apache Impala Apache Impala 4.5.2 has a path traversal flaw (CWE-23) in how the trusted_jar_paths startup flag is applied when loading JARs. An attacker can supply a relative path whose prefix matches a configured trusted URI so Impala loads a JAR from a different location on the same local or remote filesystem, including a JAR previously uploaded through Impala DDL such as CREATE DATA SOURCE or CREATE TABLE. Path traversal cannot change the URI scheme, and the attack only works when an administrator has set trusted_jar_paths to a non-empty value. Successful exploitation can cause Impala to execute code from an attacker-controlled JAR. No public proof of concept is known, the issue is not listed in CISA KEV, and CVSS has not yet been scored. Upgrade Apache Impala to 4.5.3. Until then, leave trusted_jar_paths unset or empty unless JAR loading is required, and restrict who can run CREATE DATA SOURCE and CREATE TABLE so untrusted JARs cannot be placed on filesystems referenced by trusted paths. |
Posted by Michael Smith on Oct 06 Severity: important Affected versions: - Apache Impala 4.5.2 before 4.5.3 Description: Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't...
This source does not provide full text. Read it at seclists.org.