THREATOPS
THREAT OPSThreat News › CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token

CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token

medoss_secPublished 2026-09-08

<p>Posted by Michael Smith on Sep 08</p>Severity: critical <br /> <br /> Affected versions:<br /> <br /> - Apache Impala 4.0.0 through 4.5.1<br /> <br /> Description:<br /> <br /> Signature of Bearer token is not verified in last step of SAML2 authentication for Impala&apos;s hs2-http interface, <br /> allowing altering user name and acting as another user.<br /> <br /> This issue affects Apache I

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/686