Apache Impala 2.7-4.5 Auth Bypass Enables Arbitrary Java Exec
CVE-2026-65181 Published on September 9, 2026

Apache Impala: RCE via External Data Source Class Loading
Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Vendor Advisory NVD

Weakness Type

Improper Control of Dynamically-Managed Code Resources

The software does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements. Many languages offer powerful features that allow the programmer to dynamically create or modify existing code, or resources used by code such as variables and objects. While these features can offer significant flexibility and reduce development time, they can be extremely dangerous if attackers can directly influence these code resources in unexpected ways.


Products Associated with CVE-2026-65181

Want to know whenever a new CVE is published for Apache Impala? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Impala: