{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90466","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2026-09-11T23:18:44.474Z","datePublished":"2026-10-07T08:47:12.542Z","dateUpdated":"2026-10-07T18:46:39.669Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2026-10-07T08:47:12.542Z"},"title":"Apache Impala: Path traversal executes JARs outside trusted paths","problemTypes":[{"descriptions":[{"description":"CWE-23 Relative path traversal","lang":"en","cweId":"CWE-23","type":"CWE"}]}],"source":{"defect":["IMPALA-15345"],"discovery":"EXTERNAL"},"affected":[{"vendor":"Apache Software Foundation","product":"Apache Impala","versions":[{"status":"affected","version":"4.5.2","lessThan":"4.5.3","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"value":"Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'.\n\n\n\n\nThe startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin.\n\n\n\n\nUsers are recommended to upgrade to version 4.5.3, which fixes this issue.","lang":"en","supportingMedia":[{"type":"text/html","base64":false,"value":"<div>Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'.</div><div><br></div><div>The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack<span>&nbsp;requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin.</span></div><div><br></div><div>Users are recommended to upgrade to version 4.5.3, which fixes this issue.</div><br>"}]}],"references":[{"url":"https://lists.apache.org/thread.html/m7qbho4j1g4v7kx7pbk4z2n8p9nx6bqn","tags":["vendor-advisory"]}],"metrics":[{"other":{"type":"Textual description of severity","content":{"text":"important"}},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"credits":[{"lang":"en","value":"Andrew Rukin (Arenadata)","type":"reporter"}],"x_generator":{"engine":"Vulnogram 1.0.3"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/10/07/20"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-10-07T09:16:10.802Z"}},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":6.5,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-10-07T18:46:33.842491Z","id":"CVE-2026-90466","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-07T18:46:39.669Z"}}]}}