Executive brief
Apache HBase is a distributed database used for storing large amounts of data. A security flaw in its Thrift and REST interfaces allows unauthorized users to access or interfere with data scans initiated by other users. This could lead to unauthorized data exposure or the disruption of active database operations.
Technical details
A missing authorization check exists in the 'fetch' and 'close' steps of the Apache HBase Thrift and REST delegation services. While the 'open' step correctly identifies the scanner owner, subsequent requests only require the scanner ID without verifying that the requesting user is the original owner. An attacker with network access to these services can guess or obtain active scanner IDs to retrieve data rows from other users' sessions or prematurely terminate their scanners. The issue is resolved in versions 3.0.0-beta-2, 2.6.6, and 2.5.15.
Affected products
- Apache Software Foundation HBase 3.0.0-alpha-1 through 3.0.0-beta-1, 2.6.0 through 2.6.5, 2.5.0 through 2.5.14, 2.4.*
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory