CVE-2026-65181 PUBLISHED

Apache Impala: RCE via External Data Source Class Loading

Assigner: apache
Reserved: 21.07.2026 Published: 09.09.2026 Updated: 09.09.2026

Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Product Status

Vendor Apache Software Foundation
Product Apache Impala
Versions Default: unaffected
  • affected from 2.7.0 to 4.5.1 (incl.)

Credits

  • zhaokaifei ChinaTelecom reporter

References

Problem Types

  • CWE-913 Improper Control of Dynamically-Managed Code Resources CWE