Impala 4.5.2 Stored XSS via Table Alias in Web UI (upgrade to 4.5.3)
CVE-2026-93684 Published on October 7, 2026

Apache Impala: Stored XSS in Impala query plans
An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). Users are recommended to upgrade to version 4.5.3.

Vendor Advisory NVD

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2026-93684 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2026-93684

Want to know whenever a new CVE is published for Apache Impala? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Impala: