PT-2026-107433 · Impala · Impala

·

CVE-2026-90466

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Impala version 4.5.2
Description A path traversal issue exists in the trusted jar paths startup flag, which is used to reference URIs for loading files from local or remote filesystems. This allows an attacker to load a controlled JAR file via a relative path, provided the prefix matches a path already specified in trusted jar paths. While the schema cannot be overridden, this can lead to the execution of a JAR previously uploaded to a different location on the filesystem using Impala DDLs, such as CREATE DATA SOURCE and CREATE TABLE. This issue requires the trusted jar paths flag to be configured with a non-empty value by an administrator.
Recommendations Upgrade to version 4.5.3.

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90466

Affected Products

Impala