CVE-2026-57866 PUBLISHED

Apache Impala: Secrets Exfiltration via SSRF

Assigner: apache
Reserved: 25.06.2026 Published: 09.09.2026 Updated: 09.09.2026

Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the hadoop.security.credential.provider.path property of core-site.xml. The secret's key must be known to the user.

Product Status

Vendor Apache Software Foundation
Product Apache Impala
Versions Default: unaffected
  • affected from 4.4.0 to 4.5.1 (incl.)

Credits

  • Andrey Rukin (Arenadata) reporter

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE