CVE-2026-56207
Apache Impala versions 4.0.0 and newer contain a flaw that lets attackers change the user name in SAML2 authentication, effectively impersonating other users. The vulnerability is in the hs2-http interface and is not mitigated by the token signature check. It can be fixed by upgrading to a patched version.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Impala 4.0.0 and later (hs2-http interface).
Real-world impact
An attacker who can send a crafted SAML2 request can alter the user name in the authentication flow and act as any other user, gaining full access to data and services.
Why this severity
The CVSS score of 9.8 reflects that the flaw requires no authentication or user interaction, and it gives an attacker complete confidentiality, integrity, and availability compromise. The lack of a verification step in the final authentication step makes the vulnerability especially severe.
What to do about it
- 011. Upgrade Apache Impala to version 4.5.2 or later.
- 022. Restart the Impala service to apply the update.
NVD-referenced vendor advisory
Timeline
- Sep 9, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- lists.apache.org/thread/20cov78py0zqzx7dyq39…mailing listvendor advisory
- openwall.com/lists/oss-security/2026/09/…mailing listthird party advisory