CVE-2026-49326
Last modified
CVE-2026-49326 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for identifying the scanner instances stored at server side. We missed the owner check in fetch and close steps which means a user can fetch rows from the scanner which is opened by other users, and close scanners which belongs to other users. This issue affects Apache HBase:from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, through 2.4.*. Users are recommended to upgrade to version 3.0.0-beta-2, 2.6.6 and 2.5.15, which fixes the issue.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for identifying the scanner instances stored at server side. We missed the owner check in fetch and close steps which means a user can fetch rows from the scanner which is opened by other users, and close scanners which belongs to other users. This issue affects Apache HBase:from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, through 2.4.*. Users are recommended to upgrade to version 3.0.0-beta-2, 2.6.6 and 2.5.15, which fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Hbase | < 2.5.15 | — |
| Apache | Hbase | >= 2.6.0, < 2.6.6 | — |
| Apache | Hbase | 3.0.0 | Alpha1 |
References
- https://lists.apache.org/thread/f4l4sjgwb9tb04cqnkpgl6gy3slgvcsjMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/24/23Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-49326?
How severe is CVE-2026-49326?
How do I fix CVE-2026-49326?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-49319Remote Keyless Entry System (RKES), using the 433 MHz key fo…6.9
- CVE-2026-4932IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW10…4.2
- CVE-2026-49322Weak authentication in the Wireless Control Module (WCM) of …4.3
- CVE-2026-49323Weak authentication between the Wireless Control Module (WCM…4.3
- CVE-2026-49324Uncontrolled resource consumption in the Wireless Control Mo…4.6
- CVE-2026-49325Improper handling of physical conditions in the bike-shutdow…4.6
- CVE-2026-49328Server-Side Request Forgery (SSRF) in the UrlImageConverter …5.3
- CVE-2026-4933Incorrect Authorization vulnerability in Drupal Unpublished …7.5
- CVE-2026-49331A flaw was found in openshift/oauth-proxy. On paths configur…6.5
- CVE-2026-49332A flaw was found in openshift/oauth-proxy. The proxy sets au…8.5
- CVE-2026-49336@microsoft/kiota-http-fetchlibrary provides TypeScript libra…5.5
- CVE-2026-49337libde265 is an open source implementation of the h.265 video…4.3
Are you affected by CVE-2026-49326?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
