SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-56207

CRITICAL · CVSS 9.8 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-11

CyberRota Analysis

AI-Generated

Apache Impala versions 4.0.0 and above are vulnerable due to the lack of verification for the signature of Bearer tokens in the final step of SAML2 authentication, potentially allowing an attacker to impersonate another user. This vulnerability poses a significant risk to user identity and access control. Organizations utilizing affected versions should prioritize upgrading to version 4.5.2 to mitigate this security risk.

CVE
CVE-2026-56207
Severity
CRITICAL
CVSS
9.8
EPSS
0.47%
Apache

Original NVD Description

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)