Skip to content
Rota Nacional

Cyber ·

CVE-2026-93684: Stored XSS in Apache Impala query plans

A user with SELECT permission can insert JavaScript into a table alias, which runs in the browser of whoever opens the query plan in the web interface. Affects versions 2.7.0 to 4.5.2; the fix is in 4.5.3.

On October 6, the oss-sec security list disclosed CVE-2026-93684, a moderate-severity flaw in Apache Impala. It is classified as stored XSS (CWE-79). The problem affects versions 2.7.0 through 4.5.2. A SQL user with only SELECT permission can insert JavaScript into a table alias. That code runs in the browser of another user when they open the query plan in the Impala web interface. The discoverer is credited in the original notice. The recommended action is to upgrade to version 4.5.3.

The relevance lies in the privilege required: read access is enough to insert the malicious content, and execution happens for whoever views the plan. Teams using Impala for data analysis should treat the upgrade as a priority and review who has access to the web interface.

Rota Nacional does not operate or patch Impala, and this page does not describe any platform feature for this flaw. For anyone using AI to study the case, take care: do not paste into models real queries, table names or plans containing personal data or credentials. Use fictitious examples.

To verify, consult the original notice on the oss-sec list and the Apache project advisories, and check the version installed in your cluster.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free