SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-54048

MEDIUM · CVSS 5.3 EPSS 0.58%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-11

CyberRota Analysis

AI-Generated

Impala versions 2.0.0 to 4.5.1 are vulnerable due to the ability to specify external schema URLs, potentially allowing attackers to trigger unauthorized GET requests to internal endpoints. This could lead to the exposure of sensitive information through parsing error messages. Organizations using affected versions should prioritize upgrading to version 4.5.2 to mitigate this risk.

CVE
CVE-2026-54048
Severity
MEDIUM
CVSS
5.3
EPSS
0.58%

Original NVD Description

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)