CVE-2026-49326
Apache HBase: Thrift and REST gateways do not check scanner ownership
Technology
Apache HBase
CVSS Score
6.5 / 10.0
Affected Versions
Apache HBase (hbase-thrift) through 2.4.x, 2.5.0 to 2.5.14, 2.6.0 to 2.6.5, 3.0.0-alpha-1 to 3.0.0-beta-1
Upstream Fix
2.5.15, 2.6.6, 3.0.0-beta-2; no fix for 2.4 or older
Published
July 24, 2026
OSSeva Coverage
Fixed upstream
Description
A scan through the HBase Thrift or REST gateway has three steps: open, which returns a scanner ID, then fetch and close, which take that ID. The fetch and close steps do not check that the caller owns the scanner, so on a gateway that serves several users one user can read rows from, or close, a scanner opened by another. The advisory's range runs through every 2.4 release and has no lower bound.
Is your Apache HBase deployment affected?
If you're running Apache HBase (hbase-thrift) through 2.4.x, 2.5.0 to 2.5.14, 2.6.0 to 2.6.5, 3.0.0-alpha-1 to 3.0.0-beta-1, you need this patch. Book a discovery call to get covered.