---
id: CVE-2026-65181
title: >-
  Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a
  client with privileges to upload a file to remote storage and create a table
  to execute arbitrary Java code.

  Users are recommended to upgrade to version 4.5.2, w…
summary: >-
  Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a
  client with privileges to upload a file to remote storage and create a table
  to execute arbitrary Java code.

  Users are recommended to upgrade to version 4.5.2, w…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-913
vendor: apache
product: impala
affected:
  - 'impala >= 2.7.0, < 4.5.2'
patched:
  - impala 4.5.2
published: '2026-09-09'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T20:36:32.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-65181'
references:
  - url: 'https://lists.apache.org/thread/2ty3srsh96j86xxg4g1hbo5rwvszwcnl'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/08/24'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.00564
epssPercentile: 0.45693
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T20:22:02.630909Z'
ingestedAt: '2026-09-09T11:07:21.295Z'
---

## Overview

Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code.
Users are recommended to upgrade to version 4.5.2, which fixes this issue.

## Affected

- `impala >= 2.7.0, < 4.5.2`

## Remediation

Upgrade past the affected range:

- `impala 4.5.2`
