Apache Impala 4.5.2 JWT/OAuth Auth Bypass in Executor Webserver
CVE-2026-97720 Published on October 7, 2026
Apache Impala: Impala Executor Webserver Auth Bypass
Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens. Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT.
Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.
Vulnerability Analysis
CVE-2026-97720 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Incorrect Implementation of Authentication Algorithm
The requirements for the software dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect. This incorrect implementation may allow authentication to be bypassed.
Products Associated with CVE-2026-97720
Want to know whenever a new CVE is published for Apache Impala? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Impala:- Version 4.1.0, <= 4.5.2 is affected.