CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token
Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user.
This issue affects Apache Impala: >=4.0.0.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Impalato a version that resolves this vulnerability.Fixed in 4.5.2
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Apache Impala versions 4.0.0 and later are affected when using the hs2-http interface with SAML2 authentication.
What does an attacker need to exploit it?
An attacker needs to provide a forged or altered bearer token during the final SAML2 authentication step. Because the token signature is not verified at that step, the attacker can alter the user name and impersonate another user.
Is there a fixed version available?
Yes. Upgrade Apache Impala to version 4.5.2, which fixes the issue.