CVE-2026-93684: Apache Impala: Stored XSS in Impala query plans
An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). Users are recommended to upgrade to version 4.5.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Impalato a version that resolves this vulnerability.Fixed in 4.5.3
Event History
Frequently Asked Questions
Who can exploit this issue, and what interaction is required?
An Impala SQL user with only SELECT permission can craft a table alias containing JavaScript. The script executes when another user opens the affected query plan in Impala's Web UI.
Which deployments are affected?
Apache Impala versions up to and including 4.5.2 are affected. The issue involves viewing query plans through the Impala Web UI.
What should teams do to remediate the issue?
Upgrade Apache Impala to version 4.5.3.