CVE WATCH / VULNERABILITY DETAIL

CVE-2026-97720

CRITICALCVSS 9.1NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens.  Bearer token (JWT) signatures are n

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-97720 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-97720

CRITICALCVSS 9.1NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens.  Bearer token (JWT) signatures are n

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]