CVE-2026-56207
Dashboard / Vulnerabilities / CVE-2026-56207
CVE-2026-56207
Published: 9 Sept 2026Last Modified: 12 Sept 2026
Summary: Apache Impala: SAML authentication bypass via forged bearer token
Details: Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
References: http://www.openwall.com/lists/oss-security/2026/09/08/22, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56207.json, https://lists.apache.org/thread/20cov78py0zqzx7dyq39ktythkwn91zs, https://nvd.nist.gov/vuln/detail/CVE-2026-56207
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 1950394e56927cac2f101324fa0397aa3d378f2d
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
