
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56207 is a critical authentication bypass vulnerability in Apache Impala's hs2-http interface, where the Bearer token signature is not verified during the final step of SAML2 authentication. This allows an unauthenticated attacker to forge Bearer tokens, alter the authenticated username, and impersonate any user. The vulnerability affects Apache Impala versions 4.0.0 through 4.5.1, and was disclosed on September 8, 2026, with a fix available in version 4.5.2. It carries a CVSS v3.1 base score of 9.8 (Critical) (Apache Advisory, OSS-Sec).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature): during the last step of SAML2 authentication for Impala's hs2-http interface, the cryptographic signature of the Bearer token is not validated, meaning the token's integrity and authenticity are never confirmed. An unauthenticated network attacker can craft or modify a Bearer token to specify an arbitrary username, effectively bypassing the authentication mechanism entirely. No special privileges or user interaction are required, and the attack is automatable over the network. The vulnerability was reported by Andrew Rukin of Arenadata (OSS-Sec, GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to impersonate any user — including administrators — on Apache Impala, gaining full access to query and manipulate data with the privileges of the impersonated account. This results in high confidentiality, integrity, and availability impact, as attackers can read sensitive data, alter or delete datasets, and potentially disrupt Impala services. The scope of impact is limited to the Impala instance itself, but lateral movement within a data platform environment is possible if impersonated accounts have broad permissions (Apache Advisory, OSS-Sec).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is automatable and requires no authentication or user interaction, making it highly attractive for exploitation once details become more widely known. The EPSS score is approximately 0.158% (Feedly data) to 0.468% (GitHub Advisory), placing it in the 39th percentile for exploitation probability within 30 days. No threat actor attribution or CISA KEV catalog listing has been reported as of the disclosure date.
Authorization header.Authorization header from untrusted or external IP addresses.The primary remediation is to upgrade Apache Impala to version 4.5.2 or later, which includes the fix for this vulnerability (Apache Advisory). If immediate patching is not feasible, restrict network access to the hs2-http interface to trusted internal sources only using firewall rules or network segmentation. Additionally, monitor Impala audit logs for suspicious authentication activity or unusual user impersonation patterns as a compensating control.
The vulnerability was disclosed via the Apache security mailing list and the oss-security list on September 8, 2026, with coverage appearing on security news aggregators such as SecurityOnline.info and VulDB shortly after (OSS-Sec). The Bulwark Black blog published analysis linking the flaw to broader SAML/SSRF risks in zero-trust data platforms. No major vendor statements beyond the Apache advisory or notable researcher commentary have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."