Get real-time updates on Telegram
Verified
CVE-2026-93684: Apache Impala 2.7.0 through 4.5.2
Affected technology
Apache Impala · 2.7.0 through 4.5.2
Apache Software Foundation
Description’s affected range: up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI
Component: Not specified by the source
What an attacker can do
The source does not specify what an attacker can achieve.
- CWE
- CWE-79
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-07 13:20:35.851963+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-07 11:49:32.540646+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-93684.html