Improper Verification of Cryptographic Signature in Apache Impala - CVE-2026-56207
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to impersonate another user.
The vulnerability exists due to improper verification of cryptographic signatures in the hs2-http interface during the final step of SAML2 authentication when processing bearer tokens. A remote attacker can submit a forged bearer token with an altered user name to impersonate another user.