CVE-2026-93684: Apache Impala: Stored XSS in Impala query plans
Apache Impala stored XSS lets SELECT-only users run script in the query-plan Web UI.
CVE-2026-93684 is a moderate stored cross-site scripting flaw in Apache Impala 2.7.0 through 4.5.2. An SQL user with only SELECT permission can place JavaScript in a table alias that executes in another user's browser when that user opens the query plan in Impala's Web UI. Apache recommends upgrading to 4.5.3. Andrew Rukin of Arenadata is credited, and in-the-wild exploitation is not reported.
- Stored XSS (CWE-79) via JavaScript in a table alias
- A user with only SELECT permission can plant the payload
- Script runs when another user opens the query plan in the Web UI
- Fixed in Apache Impala 4.5.3; finder Andrew Rukin of Arenadata
Vulnerabilities mentionedAll →
- CVE-2026-936845.4—Stored XSS in Apache Impala query-plan Web UIpublished · Apache Impala
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-93684 | Stored XSS in Apache Impala query-plan Web UI Apache Impala through version 4.5.2 has a stored cross-site scripting flaw (CWE-79) in how query plans are shown in the Web UI. An SQL user who has only SELECT permission can place JavaScript in a table alias; that script is stored with the query and runs in another user's browser when that user opens the query plan. Impact is limited to the browser session of whoever views the plan (session theft or actions as that user in the Web UI), not remote code execution on the Impala cluster itself. Anyone running an affected Impala deployment whose users share the Web UI is exposed. There is no known public proof of concept and no report of exploitation in the wild; the issue is not on the CISA KEV list. Upgrade Apache Impala to 4.5.3 or later. Until then, restrict access to the Impala Web UI (especially query-plan views) to trusted operators and review query history for suspicious table aliases containing script-like content. |
Posted by Michael Smith on Oct 06 Severity: moderate Affected versions: - Apache Impala 2.7.0 through 4.5.2 Description: An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). Users are recommended to upgrade to version 4.5.3. Credit: Andrew Rukin (Arenadata) (finder)...
This source does not provide full text. Read it at seclists.org.