Junglewise Threat Intelligence

CVE-2026-49326: Apache HBase missing authorization in Thrift and REST services

CVE-2026-49326 · Severity: info · CVSS 0 · Published 2026-07-24

Vendors: Apache Software Foundation.

Executive brief

Apache HBase is a distributed database used for storing large amounts of data. A security flaw in its Thrift and REST interfaces allows unauthorized users to access or interfere with data scans initiated by other users. This could lead to unauthorized data exposure or the disruption of active database operations.

Technical details

A missing authorization check exists in the 'fetch' and 'close' steps of the Apache HBase Thrift and REST delegation services. While the 'open' step correctly identifies the scanner owner, subsequent requests only require the scanner ID without verifying that the requesting user is the original owner. An attacker with network access to these services can guess or obtain active scanner IDs to retrieve data rows from other users' sessions or prematurely terminate their scanners. The issue is resolved in versions 3.0.0-beta-2, 2.6.6, and 2.5.15.

Affected products

  • Apache Software Foundation HBase 3.0.0-alpha-1 through 3.0.0-beta-1, 2.6.0 through 2.6.5, 2.5.0 through 2.5.14, 2.4.*

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References