Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-90466— Apache Impala: Path traversal executes JARs outside trusted paths

Quick assessment

Affected
Apache Software Foundation Apache Impala
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Impala 4.5.2 中的 存在路径遍历漏洞,允许攻击者通过相对路径加载受控的 JAR 文件,前提是该相对路径的前缀匹配 中指定的路径。 启动参数 引用了用于从本地或远程文件系统加载文件的统一资源标识符(URI)。虽然路径遍历无法覆盖协议(schema),但可能导致通过 Impala DDL 语句(如 CREATE DATA SOURCE 和 CREATE TABLE)将已上传至该文件系统中其他位置的 JAR 文件加载到系统中。只有当存在受信任路径时,路径遍历攻击才得以实施,因此该攻击要求 Impala 管理员

AI Predicted 7.5 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90466

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Impala: Path traversal executes JARs outside trusted paths
Source: CVE Program / CVE List V5
Vulnerability Description
Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin. Users are recommended to upgrade to version 4.5.3, which fixes this issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
相对路径遍历
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Impala 4.5.2 ~ 4.5.3 -

II. Public POCs for CVE-2026-90466

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90466

请登录查看更多情报信息。

Other References for CVE-2026-90466 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-07 · 6 CVEs total

CVE-2026-97146 4.8 MEDIUM Apache YuniKorn: Admission control bypass via system label forgery
CVE-2026-78243 2.1 LOW Apache YuniKorn: LDAP Group provider panics on lowercase attribute name
CVE-2026-92393 2.0 LOW Apache YuniKorn: Admission control bypass via workload UPDATE operation
CVE-2026-93684 Apache Impala: Stored XSS in Impala query plans
CVE-2026-97720 Apache Impala: Impala Executor Webserver Auth Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-90466

No comments yet


Leave a comment