THREAT OPS › Threat News › CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token
CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token
<p>Posted by Michael Smith on Sep 08</p>Severity: critical <br /> <br /> Affected versions:<br /> <br /> - Apache Impala 4.0.0 through 4.5.1<br /> <br /> Description:<br /> <br /> Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, <br /> allowing altering user name and acting as another user.<br /> <br /> This issue affects Apache I
Indicators of compromise
- CVE-2026-56207cve
Original source: https://seclists.org/oss-sec/2026/q3/686