CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6772

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading

CVE-2026-65181 is a remote code execution vulnerability in Apache Impala versions 2.7.0 through 4.5.1 that allows an authorized client to execute arbitrary Java code by uploading a file to remote storage and creating an external data source table. The vulnerability stems from insufficient authorization controls on Data Source tables. Apache has released version 4.5.2 to address this issue.

Why it matters: Organizations running Impala 2.7 through 4.5.1 must upgrade to 4.5.2 immediately, since any authenticated user with upload privileges can achieve remote code execution (RCE) on the cluster.

VendorsOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary