SB2026082596 - Missing Authorization in Apache HBase
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Authorization (CVE-ID: CVE-2026-49326)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information and disrupt other users' scan operations.
The vulnerability exists due to improper access control in the thrift and rest delegation service scanner handling when processing fetch and close requests for existing scanner instances. A remote user can supply a scanner identifier associated with another user's scan operation to disclose sensitive information and disrupt other users' scan operations.
The issue affects the fetch and close steps of the scan workflow after a scanner instance has been opened on the server.
Remediation
Install update from vendor's website.