Web Server Authentication Flaw in Apache Impala
CVE-2026-97720

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
7 October 2026

What is CVE-2026-97720?

A significant authentication misconfiguration exists in Apache Impala versions up to and including 4.5.2, where the webserver's JWT/OAuth authentication implementation is flawed. This flaw allows attackers to gain unauthorized access to resources by leveraging improperly validated Bearer token signatures. Consequently, the webserver may accept any valid JWT, exposing sensitive information and potentially compromising system integrity. To mitigate this risk, users are strongly advised to disable JWT/OAuth authorization for Impala executors or upgrade to version 4.5.3, which addresses this critical oversight.

Affected Version(s)

Apache Impala 4.1.0 <= 4.5.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
.