A vulnerability described as critical has been identified in Apache HBase up to 2.5.14/2.6.5/3.0.0 . Impacted is an unknown function of the component Thrift/Rest Delegation Service . The manipulation results in improper authorization. This vulnerability is identified as CVE-2026-49326 . The attack can be executed remotely. There is not any exploit available. Upgrading the affected component is recommended.