CVE-2026-97720: Apache Impala: Impala Executor Webserver Auth Bypass
Apache Impala executor web servers skip JWT signature checks, allowing authentication bypass.
CVE-2026-97720 is a low-severity authentication bypass in Apache Impala 4.1.0 through 4.5.2. Executor web servers configured to accept JWT or OAuth tokens do not validate bearer-token signatures and can accept arbitrary tokens, exposing resources they serve. The advisory does not report exploitation in the wild.
- Affects Apache Impala 4.1.0 through 4.5.2
- Executor web servers do not validate JWT bearer signatures
- Applies when the web server accepts JWT or OAuth tokens
- Apache rated the issue low; no exploitation reported
Vulnerabilities mentionedAll →
- CVE-2026-977209.1—JWT signature bypass in Apache Impala executor webserverpublished · Apache Software Foundation Apache Impala
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-97720 | JWT signature bypass in Apache Impala executor webserver Apache Impala executors through version 4.5.2 incorrectly implement JWT and OAuth authentication on the executor webserver. When that webserver is configured to accept bearer tokens, JWT signatures are not validated, so any well-formed JWT is accepted. An attacker who can reach the webserver can then access resources it serves without a legitimately signed token. Only Impala deployments that enable JWT/OAuth on executor webservers are affected; version 4.5.3 fixes the issue. No public proof of concept is known, and there is no report of exploitation in the wild. Do: Upgrade Apache Impala to 4.5.3, or disable JWT/OAuth authentication on Impala executors until you can upgrade. Limit executor webserver access to trusted networks and confirm whether JWT/OAuth is enabled on those webservers. |
Posted by Michael Smith on Oct 06 Severity: low Affected versions: - Apache Impala 4.1.0 through 4.5.2 Description: Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens. Bearer token (JWT) signatures are not validated resulting in the webserver accepting any...
This source does not provide full text. Read it at seclists.org.