CVE-2026-49326

CVE-2026-49326: Apache HBase: Missing scanner instance owner check in thrift delegation service

Vendor Apache Software Foundation
Product Apache HBase
Weakness CWE-862 · Missing authorization
Published July 24, 2026
Last update July 24, 2026

CVSS base score

What the vulnerability does

01Description

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for identifying the scanner instances stored at server side. We missed the owner check in fetch and close steps which means a user can fetch rows from the scanner which is opened by other users, and close scanners which belongs to other users. This issue affects Apache HBase:from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, through 2.4.*. Users are recommended to upgrade to version 3.0.0-beta-2, 2.6.6 and 2.5.15, which fixes the issue.

Key dates

02Disclosure timeline

July 24, 2026 CVE published
July 24, 2026 Record updated

Related vulnerabilities

04Related CVE