Path Traversal Vulnerability in Impala Affects Apache Software Foundation Products
CVE-2026-90466

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
7 October 2026

What is CVE-2026-90466?

The Impala 4.5.2 version contains a path traversal vulnerability that allows an attacker to load a malicious JAR file through a relative path. This occurs when the 'trusted_jar_paths' configuration is manipulated by an attacker. Such an exploit can occur if the Impala administrator has defined non-empty trusted paths. It is critical for users to update to version 4.5.3, where this issue has been addressed, to secure their systems against this vulnerability.

Affected Version(s)

Apache Impala 4.5.2 < 4.5.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
.