Apache Impala 4.5.3 fixes three flaws, none exploited
Apache disclosed three Impala flaws through 4.5.2—path traversal, stored XSS, and JWT auth bypass—fixed in 4.5.3, with no exploitation reported.
On 7 October 2026, oss-security carried three Apache advisories for separate flaws in Apache Impala, all present through 4.5.2 and addressed by upgrading to 4.5.3. CVE-2026-90466, rated important, is limited in the report to 4.5.2 before 4.5.3: path traversal of trusted_jar_paths lets a relative path whose prefix matches a configured trusted URI load an attacker-controlled JAR referenced by the startup flag on a local or remote filesystem. CVE-2026-93684, rated moderate, is stored cross-site scripting (CWE-79) from 2.7.0 through 4.5.2; a SQL user with only SELECT permission can put JavaScript in a table alias that executes in another user's browser when that user opens the query plan in the Web UI, and Andrew Rukin of Arenadata is credited. CVE-2026-97720, rated low, affects 4.1.0 through 4.5.2: executor web servers configured for JWT or OAuth do not validate bearer-token signatures and can accept arbitrary tokens, exposing resources they serve. The three reports do not disagree; they describe different issues, and none reports exploitation in the wild.
- CVE-2026-90466, rated important, affects Apache Impala 4.5.2 before 4.5.3: a relative path whose prefix matches a trusted_jar_paths URI can load an attacker-controlled JAR from a local or remote filesystem.
- CVE-2026-93684, rated moderate (CWE-79), affects Impala 2.7.0 through 4.5.2: a user with only SELECT permission can place JavaScript in a table alias that runs when another user opens the query plan in the Web UI.
- CVE-2026-97720, rated low, affects Impala 4.1.0 through 4.5.2: executor web servers that accept JWT or OAuth tokens do not validate bearer-token signatures and may accept arbitrary tokens.
- Apache recommends upgrading to Impala 4.5.3.
- Andrew Rukin of Arenadata is credited for CVE-2026-93684.
- All three oss-security reports, dated 2026-10-07, say in-the-wild exploitation is not reported.
Coverage timelineoldest first · each row is one article
- · 2d agoCVE-2026-90466: Apache Impala: Path traversal executes JARs outside trusted paths
oss-security· 55
Apache Impala 4.5.2 path traversal can load attacker-controlled JARs outside trusted_jar_paths.
- · 2d agoCVE-2026-93684: Apache Impala: Stored XSS in Impala query plans
oss-security· 44
Apache Impala stored XSS lets SELECT-only users run script in the query-plan Web UI.
- · 2d agoCVE-2026-97720: Apache Impala: Impala Executor Webserver Auth Bypass
oss-security· 38
Apache Impala executor web servers skip JWT signature checks, allowing authentication bypass.
Vulnerabilities in this storyAll →
- CVE-2026-904666.5—Path traversal loads untrusted JARs in Apache Impalapublished · Apache Impala+1 related
- CVE-2026-977209.1—JWT signature bypass in Apache Impala executor webserverpublished · Apache Software Foundation Apache Impala
| CVE | Vulnerability |
|---|