---
id: CVE-2026-90466
title: >-
  Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an
  attacker-controlled JAR to be loaded via a relative path where the prefix
  matches a path specified in 'trusted_jar_paths'.





  The startup flag 'trusted_jar_paths' reference…
summary: >-
  Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an
  attacker-controlled JAR to be loaded via a relative path where the prefix
  matches a path specified in 'trusted_jar_paths'.





  The startup flag 'trusted_jar_paths' reference…
severity: none
cwe:
  - CWE-23
vendor: Apache Software Foundation
product: Apache Impala
affected:
  - apache_impala >= 4.5.2 < 4.5.3
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T10:17:42.140'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90466'
references:
  - url: 'https://lists.apache.org/thread.html/m7qbho4j1g4v7kx7pbk4z2n8p9nx6bqn'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/10/07/20'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T09:22:30.529Z'
---

## Overview

Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'.




The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin.




Users are recommended to upgrade to version 4.5.3, which fixes this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
