Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-49326

Apache HBase: Thrift and REST gateways do not check scanner ownership

Technology

Apache HBase

CVSS Score

6.5 / 10.0

Affected Versions

Apache HBase (hbase-thrift) through 2.4.x, 2.5.0 to 2.5.14, 2.6.0 to 2.6.5, 3.0.0-alpha-1 to 3.0.0-beta-1

Upstream Fix

2.5.15, 2.6.6, 3.0.0-beta-2; no fix for 2.4 or older

Published

July 24, 2026

OSSeva Coverage

Fixed upstream

Description

A scan through the HBase Thrift or REST gateway has three steps: open, which returns a scanner ID, then fetch and close, which take that ID. The fetch and close steps do not check that the caller owns the scanner, so on a gateway that serves several users one user can read rows from, or close, a scanner opened by another. The advisory's range runs through every 2.4 release and has no lower bound.

Upstream record: NVD · CVE.org

Is your Apache HBase deployment affected?

If you're running Apache HBase (hbase-thrift) through 2.4.x, 2.5.0 to 2.5.14, 2.6.0 to 2.6.5, 3.0.0-alpha-1 to 3.0.0-beta-1, you need this patch. Book a discovery call to get covered.