CVE-2026-90466: CWE-23 Relative path traversal in Apache Software Foundation Apache Impala
Description
Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin. Users are recommended to upgrade to version 4.5.3, which fixes this issue.
CVSS v3.1
Score 6.5medium
Affected software
Apache Software Foundation
Apache Impala
pkg:maven/org.apache.impala/impalaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-90466 is a relative path traversal vulnerability in Apache Impala 4.5.2 affecting the 'trusted_jar_paths' startup flag. This flag references URIs for loading files from local or remote filesystems. An attacker can exploit the flaw by using a relative path that matches a prefix in 'trusted_jar_paths' to load an attacker-controlled JAR file uploaded elsewhere in the filesystem via Impala DDL commands such as CREATE DATA SOURCE and CREATE TABLE. The vulnerability does not allow overriding the URI schema but enables loading unauthorized JARs if a trusted path is configured. The issue is fixed in Apache Impala 4.5.3.
Potential Impact
Successful exploitation allows an attacker to load a malicious JAR file into Apache Impala by leveraging relative path traversal within the trusted JAR loading mechanism. This could lead to execution of unauthorized code within the Impala environment. The attack requires that the 'trusted_jar_paths' configuration is non-empty, limiting the exposure to systems where this setting is enabled.
Mitigation Recommendations
Users should upgrade Apache Impala to version 4.5.3 or later, where this vulnerability is fixed. No other mitigations are specified. If upgrading immediately is not possible, administrators should consider disabling or carefully restricting the 'trusted_jar_paths' configuration to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-09-11T23:18:44.474Z
- State
- PUBLISHED
Threat ID: 6ac60afc2cdf04f65630e9cf
Added to database: 10/07/2026, 09:03:56 UTC
Last enriched: 10/07/2026, 09:18:38 UTC
Last updated: 10/07/2026, 19:18:59 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.