THREATOPS
THREAT OPSThreat News › CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF

CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF

medoss_secPublished 2026-09-08

<p>Posted by Michael Smith on Sep 08</p>Severity: important <br /> <br /> Affected versions:<br /> <br /> - Apache Impala 4.4.0 through 4.5.1<br /> <br /> Description:<br /> <br /> Server side request forgery in Apache Impala versions 4.4.x and 4.5.x.  Authenticated Impala users with permissions to <br /> execute the ai_generate_text() function can exfiltrate secrets provided by the credential pro

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/687