Description
Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.credential.provider.path` property of `core-site.xml`. The secret's key must be known to the user.
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach via SSRF
Action: Patch
AI Analysis

Impact

Server side request forgery exists in 4.4.x and 4.5.x. Authenticated users who have permission to execute the ai_generate_text() function can supply arbitrary URLs; Impala will perform outbound requests to those URLs and can retrieve data provided by the credential providers configured in the hadoop.security.credential.provider.path property of core‑site.xml. The secret’s key must be known to the user in order to exfiltrate the credential value. The result is that sensitive credentials stored in Hadoop credential providers can be exfiltrated through the Impala server, compromising confidentiality.

Affected Systems

The vulnerability affects Apache Impala database engine versions 4.4.x and 4.5.x. An attacker must authenticate to Impala and possess the privilege to run ai_generate_text() in order to exploit the flaw. The configuration setting hadoop.security.credential.provider.path in core‑site.xml must specify credential providers for the exfiltration to succeed.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity risk. The EPSS score of <1% suggests the probability of exploitation remains low, flaw is not listed in the CISA KEV catalog, indicating no known public exploits at execute ai_generate_text() can use the SSRF flaw to exfiltrate secrets from Hadoop credential providers when the credential key is known, potentially compromising sensitive credentials. The flaw is present in both 4.4.x and 4.5.x builds of Impala. Although the attack surface is limited to users inside the Impala environment, the confidentiality impact remains significant, and the availability of a high‑severity score warrants prompt remediation.

Generated by OpenCVE AI on September 10, 2026 at 23:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Apache Impala released by the Apache Software Foundation_generate_text() function to trusted users only by applying the minimal necessary privilege model.
  • Remove or comment out the hadoop.security.credential.provider.path entry in core‑site.xml so that Impala cannot load credential providers.
  • Implement network monitoring on the Impala server to detect unexpected outbound HTTP requests.

Generated by OpenCVE AI on September 10, 2026 at 23:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache impala
CPEs cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache impala

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References

Wed, 09 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.credential.provider.path` property of `core-site.xml`. The secret's key must be known to the user.
Title Apache Impala: Secrets Exfiltration via SSRF
Weaknesses CWE-918
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T18:13:02.052Z

Reserved: 2026-06-25T21:30:09.873Z

Link: CVE-2026-57866

cve-icon Vulnrichment

Updated: 2026-09-09T11:10:47.779Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T11:17:14.953

Modified: 2026-09-10T20:36:43.880

Link: CVE-2026-57866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:30:12Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)