Description
Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens.  Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT.
Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized Access to Impala Executor Webserver Resources
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from an improper implementation of JWT/OAuth authentication in Apache Impala executors up to version 4.5.2, which fails to validate bearer token signatures. As a result, any token that is syntactically valid is accepted, allowing an attacker to bypass authentication and access resources served by the executor’s webserver. This leads to unauthorized disclosure of data or code hosted by the executor and can be exploited for further compromise.

Affected Systems

Vendors affected include the Apache Software Foundation’s Impala product. All releases through version 4.5.2 are impacted; versions 4.5.3 and later contain the fix. The weakness is limited to executors configured to use JWT/OAuth authentication.

Risk and Exploitability

Although EPSS data is not available, the vulnerability is not listed in CISA's KEV catalog, the lack of signature validation represents a high severity flaw by CWE‑303 standards. Exploitation requires a valid JWT structure but not a valid signature, which can be fabricated by an attacker with network access to the executor. The attack vector is likely remote, leveraging any channel that allows sending bearer tokens to the webserver. Given the absence of publicly disclosed exploits, actual exploitation probability may be moderate, but the potential impact warrants immediate remedial action.

Generated by OpenCVE AI on October 7, 2026 at 11:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Impala to version 4.5.3 or later to obtain the authentication fix.
  • If upgrading is not immediately feasible, disable JWT/OAuth authentication for all exposed Impala executors to eliminate the bypass vector.
  • Implement strict token validation in the executor’s webserver configuration or use a trusted library that enforces signature verification before granting access.

Generated by OpenCVE AI on October 7, 2026 at 11:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache impala
Vendors & Products Apache
Apache impala

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
References

Wed, 07 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens.  Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT. Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.
Title Apache Impala: Impala Executor Webserver Auth Bypass
Weaknesses CWE-303
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-07T09:17:05.938Z

Reserved: 2026-09-24T23:33:41.006Z

Link: CVE-2026-97720

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T09:17:06.333

Modified: 2026-10-07T10:17:47.047

Link: CVE-2026-97720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T11:15:15Z

Weaknesses
  • CWE-303

    Incorrect Implementation of Authentication Algorithm