CVE-2026-56207 PUBLISHED

Apache Impala: SAML authentication bypass via forged bearer token

Assigner: apache
Reserved: 19.06.2026 Published: 09.09.2026 Updated: 09.09.2026

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user.

This issue affects Apache Impala: >=4.0.0.

Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Product Status

Vendor Apache Software Foundation
Product Apache Impala
Versions Default: unaffected
  • affected from 4.0.0 to 4.5.1 (incl.)

Credits

  • Andrew Rukin (Arenadata) reporter

References

Problem Types

  • CWE-347 Improper Verification of Cryptographic Signature CWE