Apache Impala 4.0+ SAML2 Bearer Token Signature Not Verified in hs2-http
CVE-2026-56207 Published on September 9, 2026
Apache Impala: SAML authentication bypass via forged bearer token
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user.
This issue affects Apache Impala: >=4.0.0.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.
Weakness Type
Improper Verification of Cryptographic Signature
The software does not verify, or incorrectly verifies, the cryptographic signature for data.
Products Associated with CVE-2026-56207
Want to know whenever a new CVE is published for Apache Impala? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Impala:- Version 4.0.0, <= 4.5.1 is affected.