CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-93684: Apache Impala 2.7.0 through 4.5.2

Affected technology

Apache Impala · 2.7.0 through 4.5.2
Apache Software Foundation

Description’s affected range: up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI

Component: Not specified by the source

What an attacker can do

The source does not specify what an attacker can achieve.

Published

CWE
CWE-79
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-93684.html