SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-65181

HIGH · CVSS 8.1 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-11

CyberRota Analysis

AI-Generated

Impala versions 2.7 to 4.5 are vulnerable due to insufficient authorization in Data Source tables, enabling clients with upload privileges to execute arbitrary Java code by creating a table. This vulnerability poses a significant risk as it could lead to unauthorized code execution and potential data breaches. Organizations using affected Impala versions should prioritize upgrading to version 4.5.2 to mitigate this security risk.

CVE
CVE-2026-65181
Severity
HIGH
CVSS
8.1
EPSS
0.56%
Java

Original NVD Description

Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)