CVE-2026-90466
Received Received - Intake

Path Traversal in Impala 4.5.2 via trusted_jar_paths

Vulnerability report for CVE-2026-90466, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Apache Software Foundation

Description

Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attackΒ requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin. Users are recommended to upgrade to version 4.5.3, which fixes this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Apache Software Foundation Apache Impala 4.5.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in Apache Impala 4.5.2. It allows an attacker to load a malicious JAR file via a relative path that matches a trusted path configured in the 'trusted_jar_paths' flag. The attacker can exploit this to load a JAR from a different location in the filesystem using Impala DDL commands like CREATE DATA SOURCE or CREATE TABLE.

Detection Guidance

Check if 'trusted_jar_paths' is configured in Impala startup flags. Review JAR files loaded via CREATE DATA SOURCE or CREATE TABLE commands for unusual paths. Inspect Impala logs for unauthorized JAR loading attempts.

Impact Analysis

If you are an Impala administrator or user, this vulnerability could allow an attacker to execute arbitrary code on your system by loading a malicious JAR file. This could lead to unauthorized access, data breaches, or system compromise. Users are advised to upgrade to Impala 4.5.3 to mitigate this risk.

Mitigation Strategies

Upgrade Impala to version 4.5.3 or later. Disable or restrict 'trusted_jar_paths' configuration if not required. Monitor for suspicious JAR loading activities in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90466. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart