Incorrect authorization in Apache Impala - CVE-2026-65181
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary Java code.
The vulnerability exists due to insufficient authorization in Data Source tables when creating a table that loads an external data source class from a file uploaded to remote storage. A remote privileged user can upload a file to remote storage and create a table to execute arbitrary Java code.