CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6773

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF

A server-side request forgery (SSRF) vulnerability in Apache Impala 4.4.0 through 4.5.1 allows authenticated users with execute permissions on the ai_generate_text() function to exfiltrate secrets from configured credential providers. The vulnerability requires knowledge of the secret's key and affects systems using Hadoop credential provider paths in core-site.xml.

Why it matters: Organizations running Impala 4.4.x or 4.5.x must audit who has ai_generate_text() permissions and patch to a fixed version to prevent credential exposure through SSRF.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary