Executive brief
Apache Impala is a fast analytics database engine used for querying large datasets. The hs2-http interface uses SAML2 for user authentication. A vulnerability in signature verification allows attackers to forge authentication tokens and impersonate any user without valid credentials, leading to complete account takeover and unauthorized access to sensitive data.
Technical details
The vulnerability is an authentication bypass in the SAML2 authentication flow for Impala's hs2-http interface. The root cause is a missing signature verification step for the Bearer token in the final stage of SAML authentication. An unauthenticated attacker with network access can craft a forged Bearer token containing an arbitrary username and successfully authenticate as that user, bypassing all authentication controls. The attack requires no special privileges or user interaction. Apache Impala versions 4.0.0 through 4.5.1 are affected; the issue is fixed in version 4.5.2.
Affected products
- Apache Impala 4.0.0 through 4.5.1
Timeline
- 2026-09-08: disclosed
- 2026-09-09: patched: Fixed in version 4.5.2