🔐 CVE Alert

CVE-2026-93684

UNKNOWN 0.0

Apache Impala: Stored XSS in Impala query plans

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). Users are recommended to upgrade to version 4.5.3.

CWE CWE-79
Vendor apache software foundation
Product apache impala
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache impala

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache impala are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Impala
2.7.0 ≤ 4.5.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread.html/qxjj5n3vsttxbvq2n75xcy2qcrhtxowx openwall.com: http://www.openwall.com/lists/oss-security/2026/10/07/21

Credits

Andrew Rukin (Arenadata)