Skip to content
Rota Nacional

Cyber ·

CVE-2026-90466: path traversal in Apache Impala 4.5.2 when loading JARs

Advisory rated important: a crafted relative path can bypass trusted_jar_paths in Impala 4.5.2 and load an attacker-controlled JAR. The fix is in version 4.5.3.

On 6 October 2026, an advisory posted to the oss-sec list, machine-translated in the source feed, describes CVE-2026-90466 in Apache Impala. The severity is rated important. The affected version is Apache Impala 4.5.2, prior to 4.5.3. According to the description, the trusted_jar_paths startup option references URIs for loading files from local or remote filesystems. A relative path whose prefix matches a path specified in that option allows an attacker-controlled JAR to be loaded. The received text ends mid-description, so the full details cannot be confirmed from this copy. To verify, consult the original advisory named in the source, the official CVE record, and the Apache Impala project release notes. If your instance runs version 4.5.2, confirm the upgrade to 4.5.3 or later and review the paths configured in trusted_jar_paths. Rota Nacional does not patch or replace Impala and is not presented as a solution to this flaw.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free