Web Server Authentication Flaw in Apache Impala
CVE-2026-97720
Currently unrated
What is CVE-2026-97720?
A significant authentication misconfiguration exists in Apache Impala versions up to and including 4.5.2, where the webserver's JWT/OAuth authentication implementation is flawed. This flaw allows attackers to gain unauthorized access to resources by leveraging improperly validated Bearer token signatures. Consequently, the webserver may accept any valid JWT, exposing sensitive information and potentially compromising system integrity. To mitigate this risk, users are strongly advised to disable JWT/OAuth authorization for Impala executors or upgrade to version 4.5.3, which addresses this critical oversight.
Affected Version(s)
Apache Impala 4.1.0 <= 4.5.2