๐Ÿ” CVE Alert

CVE-2026-65181

HIGH 8.1

Apache Impala: RCE via External Data Source Class Loading

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

CWE CWE-913
Vendor apache software foundation
Product apache impala
Published Sep 9, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache impala

Be the first to know when new high vulnerabilities affecting apache software foundation apache impala are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Impala
2.7.0 โ‰ค 4.5.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/2ty3srsh96j86xxg4g1hbo5rwvszwcnl openwall.com: http://www.openwall.com/lists/oss-security/2026/09/08/24

Credits

๐Ÿ” zhaokaifei ChinaTelecom