Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
History

Wed, 09 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References

Wed, 09 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
Title Apache Impala: SAML authentication bypass via forged bearer token
Weaknesses CWE-347
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2026-09-09T10:36:55.238Z

Updated: 2026-09-09T11:10:45.866Z

Reserved: 2026-06-19T15:49:57.313Z

Link: CVE-2026-56207

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T11:17:14.827

Modified: 2026-09-09T15:37:09.320

Link: CVE-2026-56207

cve-icon Redhat

No data.