Description
Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'.




The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin.




Users are recommended to upgrade to version 4.5.3, which fixes this issue.
Published: 2026-10-07
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability is a classic path traversal (CWE‑23) within the 'trusted_jar_paths' configuration of Apache Impala 4.5.2. By providing a relative path that matches a suffix of a trusted URI, an attacker can trick Impala into loading a JAR file that has been uploaded to an unauthorized location through DDL statements such as CREATE DATA SOURCE or CREATE TABLE. Once loaded, the JAR’s code runs with the permissions of the Impala service, giving the attacker remote code execution capabilities on the host where Impala is running.

Affected Systems

Apache Software Foundation’s Apache Impala version 4.5.2 is affected. The issue only manifests when the Impala administrator has configured a non‑empty 'trusted_jar_paths' value. No other Impala versions are listed as vulnerable.

Risk and Exploitability

The exploit requires an attacker to have privileges to execute DDL statements that place a malicious JAR under a trusted path. The vulnerability is not listed in CISA’s KEV catalog, and no EPSS score is available. However, because the flaw can lead to full control of the Impala host and is present in a public configuration option, the risk is considered high. If exploited, an attacker can run arbitrary code within the Impala process, potentially compromising the underlying system and any data it processes.

Generated by OpenCVE AI on October 7, 2026 at 11:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Impala to version 4.5.3 or later, which removes the path traversal flaw.
  • If an upgrade cannot be performed immediately, reconfigure 'trusted_jar_paths' to be empty or limit it to directories that cannot contain attacker‑supplied JARs, and restrict the ability to create external data sources or tables that can introduce new JARs.
  • Continuously monitor Impala logs for unexpected DDL activity or JAR loading attempts and review any unusual file system access patterns.

Generated by OpenCVE AI on October 7, 2026 at 11:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache impala
Vendors & Products Apache
Apache impala

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
References

Wed, 07 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin. Users are recommended to upgrade to version 4.5.3, which fixes this issue.
Title Apache Impala: Path traversal executes JARs outside trusted paths
Weaknesses CWE-23
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-07T09:16:10.802Z

Reserved: 2026-09-11T23:18:44.474Z

Link: CVE-2026-90466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T09:17:05.987

Modified: 2026-10-07T13:35:14.410

Link: CVE-2026-90466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T11:45:16Z

Weaknesses
  • CWE-23

    Relative Path Traversal