CVE-2026-97720
Description
AI Translation Available
Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens. Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT.
Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.
303
Incorrect Implementation of Authentication Algorithm
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
http://www.openwall.com/lists/oss-security/2026/10/07/22
https://lists.apache.org/thread.html/q2qkrnko9hdv2mhqy6prm06f65n2g3h2