CVE-2026-97720

critical

Description

Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens. Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT. Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.

References

https://lists.apache.org/thread.html/q2qkrnko9hdv2mhqy6prm06f65n2g3h2

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94222

http://www.openwall.com/lists/oss-security/2026/10/07/22

Details

Source: Mitre, NVD

Published: 2026-10-07

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 9.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.00323