Skip to content
Rota Nacional

Cyber ·

CVE-2026-97720: Apache Impala accepts JWT tokens without validating their signature on the executor

Low-severity advisory: the Apache Impala executor web server does not validate JWT/OAuth token signatures, which can allow access to resources when that mode is enabled. Versions 4.1.0 through 4.5.2 are affected.

Advisory CVE-2026-97720 describes an authentication flaw in the Apache Impala executor web server. According to the text, Bearer (JWT) token signatures are not validated, so the server accepts any token in that mode. The described result is that an attacker can access resources served by the executor web server, but only when it is configured to accept JWT or OAuth tokens. The source rates the severity as low. Affected versions are 4.1.0 through 4.5.2, inclusive. The text was posted to the oss-sec list by Michael Smith on 6 October, and the feed records it on 7 October 2026. To verify, consult the oss-sec list archive for the fourth quarter of 2026 and the official Apache Impala announcement, which may list the fixed version and upgrade instructions. This news does not involve a Rota Nacional feature: the platform does not operate Impala and does not fix this flaw. For Impala users, the relevant steps are checking the version in use, confirming whether JWT/OAuth authentication is active on the executor, and assessing the web server's network exposure.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free