Missing Authorization Affecting org.apache.hbase:hbase-thrift package, versions [2.5.0,2.5.15)[2.6.0,2.6.6)[3.0.0-alpha-1,3.0.0-beta-1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.31% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEHBASE-19500661
  • published2 Sept 2026
  • disclosed24 Jul 2026
  • creditAndrew Rukin

Introduced: 24 Jul 2026

CVE-2026-49326  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade org.apache.hbase:hbase-thrift to version 2.5.15, 2.6.6, 3.0.0-beta-1 or higher.

Overview

org.apache.hbase:hbase-thrift is a HBase Thrift Server.

Affected versions of this package are vulnerable to Missing Authorization in the REST ScannerInstanceResource and Thrift HBaseServiceHandler scanner handling. An attacker can read rows from, or close, another user’s open scanner by reusing its scanner ID in a REST GET/DELETE request or Thrift scannerGet/scannerClose call. The vulnerable code binds scanner state to a shared server-side ID but does not verify that the caller owns that scanner before serving fetch or close operations. In deployments exposing the HBase REST or Thrift delegation services, this lets one authenticated user interfere with another user’s scan session and access data returned by that scanner.

CVSS Base Scores

version 4.0
version 3.1