🔐 CVE Alert

CVE-2026-90466

UNKNOWN 0.0

Apache Impala: Path traversal executes JARs outside trusted paths

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin. Users are recommended to upgrade to version 4.5.3, which fixes this issue.

CWE CWE-23
Vendor apache software foundation
Product apache impala
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache impala

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache impala are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Impala
4.5.2 < 4.5.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread.html/m7qbho4j1g4v7kx7pbk4z2n8p9nx6bqn openwall.com: http://www.openwall.com/lists/oss-security/2026/10/07/20

Credits

🔍 Andrew Rukin (Arenadata)