PatchSiren cyber security CVE debrief
CVE-2026-49326 Apache Software Foundation CVE debrief
Apache HBase has a Missing Authorization vulnerability in its thrift and rest delegation service, allowing users to fetch rows from scanners opened by other users and close scanners belonging to other users. This issue affects Apache HBase versions from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, and through 2.4.*. Users are recommended to upgrade to version 3.0.0-beta-2, 2.6.6, and 2.5.15, which fixes the issue.
- Vendor
- Apache Software Foundation
- Product
- Apache HBase
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-24
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-24
- Advisory updated
- 2026-08-06
Who should care
Users of Apache HBase, especially those using versions from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, and through 2.4.*, should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing and implementing the recommended actions provided by the vendor and monitoring their systems for potential exploitation attempts. Additionally, security teams and vulnerability management teams should prioritize patching affected systems and review compensating controls for exposed systems while remediation is scheduled and verified. Operators and platform administrators should also review the official advisory and CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Those responsible for monitoring, detection, and logs for exposed assets should check relevant logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory managers should also review and update their inventory to ensure that all affected systems are accounted for and prioritized for remediation. Those managing change windows and rollback processes should plan and execute these processes carefully to minimize disruption and ensure that all necessary precautions are taken to prevent exploitation during these times. Lastly, source tracking and incident response teams should be prepared to respond to potential exploitation attempts and have a plan in place to quickly respond to and contain any incidents that may arise. This may involve reviewing and updating incident response plans, conducting additional monitoring and logging, and ensuring that all necessary communication channels are established and tested. By taking these steps, organizations can help protect their systems and minimize the risk of exploitation. Those managing Apache HBase deployments should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should also review compens
Technical summary
The vulnerability is caused by a missing authorization check in the fetch and close steps of the scan operation in thrift/rest service. This allows users to fetch rows from scanners opened by other users and close scanners belonging to other users. The affected versions of Apache HBase are from 3.0.0-alpha-1 through 3.0.0-beta-1, from 2.6.0 through 2.6.5, from 2.5.0 through 2.5.14, and through 2.4.*. The issue can be mitigated by upgrading to version 3.0.0-beta-2, 2.6.6, and 2.5.15.
Defensive priority
Medium priority due to the potential for unauthorized data access
Recommended defensive actions
- Upgrade to version 3.0.0-beta-2, 2.6.6, and 2.5.15
- Implement proper authorization checks for scanner operations
- Monitor and restrict access to sensitive data
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD detail provide information about the vulnerability, its impact, and the affected versions of Apache HBase. The vendor advisory and third-party advisory provide additional context and mitigation strategies.
Official resources
-
CVE-2026-49326 CVE record
CVE.org
-
CVE-2026-49326 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Mailing List, Vendor Advisory
-
Mitigation or vendor reference
af854a3a-2127-422b-91ae-364da2661108 - Mailing List, Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T15:17:31.163Z and has not been modified since then. The NVD entry is currently Analyzed.