THREAT OPS › Threat News › CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading
CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading
<p>Posted by Michael Smith on Sep 08</p>Severity: important <br /> <br /> Affected versions:<br /> <br /> - Apache Impala 2.7.0 through 4.5.1<br /> <br /> Description:<br /> <br /> Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to <br /> remote storage and create a table to execute arbitrary Java code.<br /> Users are recommended
Indicators of compromise
- CVE-2026-65181cve
- https://impala.apache.org/url
Original source: https://seclists.org/oss-sec/2026/q3/688