As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading
CVE-2026-65181 is a remote code execution vulnerability in Apache Impala versions 2.7.0 through 4.5.1 that allows an authorized client to execute arbitrary Java code by uploading a file to remote storage and creating an external data source table. The vulnerability stems from insufficient authorization controls on Data Source tables. Apache has released version 4.5.2 to address this issue.
Why it matters: Organizations running Impala 2.7 through 4.5.1 must upgrade to 4.5.2 immediately, since any authenticated user with upload privileges can achieve remote code execution (RCE) on the cluster.
- Source published
- First seen by Cybersecurity Tracker