Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN875
_____________________________________________________________________

DATE                : 09/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Impala versions prior to
                                          4.5.2.
 
=====================================================================
https://lists.apache.org/thread/vh7zfn04mk0xcy8wqg9hw91x7zgy2mqc
https://lists.apache.org/thread/hfx6qjmow1pw219yh4b8gsgqv1ogh0rc
https://lists.apache.org/thread/ll7vn2png7qdv3lkp0zjwkx2vtf85g38
https://lists.apache.org/thread/cfmk1og8f513db7fktp34vyvwy02r3jh
_____________________________________________________________________

CVE-2026-65181: Apache Impala: RCE via External Data Source Class
Loading

Severity: important 

Affected versions:

- Apache Impala 2.7.0 through 4.5.1

Description:

Insufficient authorization of Data Source tables in Impala 2.7-4.5
allows a client with privileges to upload a file to remote storage and
create a table to execute arbitrary Java code.

Users are recommended to upgrade to version 4.5.2, which fixes this
issue.

Credit:

zhaokaifei ChinaTelecom (reporter)

References:

https://impala.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-65181

_____________________________________________________________________

CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF
Severity: important 

Affected versions:

- Apache Impala 4.4.0 through 4.5.1

Description:

Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.
Authenticated Impala users with permissions to execute the
ai_generate_text() function can exfiltrate secrets provided by the
credential providers configured in the
`hadoop.security.credential.provider.path` property of `core-site.xml`.
The secret's key must be known to the user.

Credit:

Andrey Rukin (Arenadata) (reporter)

References:

https://impala.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-57866

_____________________________________________________________________

CVE-2026-56207: Apache Impala: SAML authentication bypass via forged
bearer token

Severity: critical 

Affected versions:

- Apache Impala 4.0.0 through 4.5.1

Description:

Signature of Bearer token is not verified in last step of SAML2
authentication for Impala's hs2-http interface, allowing altering user
name and acting as another user.


This issue affects Apache Impala: >=4.0.0.


Users are recommended to upgrade to version 4.5.2, which fixes this
issue.

Credit:

Andrew Rukin (Arenadata) (reporter)

References:

https://impala.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-56207

_____________________________________________________________________

CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request
Forgery

Severity: important 

Affected versions:

- Apache Impala 2.0.0 through 4.5.1

Description:

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a
'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms
allows an attacker to trigger a GET request to internal endpoints they
may not have access to but that Impala does and the response my be
exposed via parsing error messages.

Users are recommended to upgrade to version 4.5.2, which fixes this
issue.

Credit:

zhaokaifei ChinaTelecom (reporter)

References:

https://impala.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-54048


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




