Apache Impala 4.0+ SAML2 Bearer Token Signature Not Verified in hs2-http
CVE-2026-56207 Published on September 9, 2026

Apache Impala: SAML authentication bypass via forged bearer token
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Vendor Advisory NVD

Weakness Type

Improper Verification of Cryptographic Signature

The software does not verify, or incorrectly verifies, the cryptographic signature for data.


Products Associated with CVE-2026-56207

Want to know whenever a new CVE is published for Apache Impala? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Impala: