# CVE-2026-56207

## Summary

- **CVE ID:** CVE-2026-56207
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-347
- **Published:** Sep 9, 2026
- **Last Modified:** Sep 9, 2026

## Description

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user.



This issue affects Apache Impala: >=4.0.0.



Users are recommended to upgrade to version 4.5.2, which fixes this issue.

## Affected Products

- Apache Software Foundation — Apache Impala (4.0.0)

## References

- [CNA](https://lists.apache.org/thread/20cov78py0zqzx7dyq39ktythkwn91zs)
- [CVE](http://www.openwall.com/lists/oss-security/2026/09/08/22)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._