Impala 4.5.2 Stored XSS via Table Alias in Web UI (upgrade to 4.5.3)
CVE-2026-93684 Published on October 7, 2026
Apache Impala: Stored XSS in Impala query plans
An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). Users are recommended to upgrade to version 4.5.3.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-93684 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-93684
Want to know whenever a new CVE is published for Apache Impala? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Impala:- Version 2.7.0, <= 4.5.2 is affected.