Executive brief
Apache Impala is a distributed SQL query engine used for real-time analytics. An authenticated attacker with permissions to execute the ai_generate_text() function can exploit a server-side request forgery vulnerability to exfiltrate sensitive credentials stored in Hadoop credential providers, leading to unauthorized access to protected resources and secrets.
Technical details
This vulnerability is a server-side request forgery (SSRF) in Apache Impala versions 4.4.x and 4.5.x affecting the ai_generate_text() function. The vulnerability allows authenticated users with execute permissions on this function to exfiltrate secrets from credential providers configured in the `hadoop.security.credential.provider.path` property of `core-site.xml`. Exploitation requires knowledge of the specific secret key name. The attack is network-based and requires prior authentication and function execution privileges. No information on patch availability is provided in the advisory.
Affected products
- Apache Impala 4.4.0 through 4.5.1
Timeline
- 2026-09-09: disclosed
- 2026-09-08: advisory