SB2026082713 - Multiple vulnerabilities in Apache Hive
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) SQL injection (CVE-ID: CVE-2026-49845)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read, modify, or affect unintended partition metadata.
The vulnerability exists due to sql injection in HiveMetaStore direct-SQL partition-name resolution paths when processing crafted partition names in metastore RPC requests. A remote user can send crafted partition names to read, modify, or affect unintended partition metadata.
The issue affects partition targeting operations such as statistics updates, truncation targets, and file-metadata cache operations, and exploitation requires direct SQL to be enabled.
2) Improper Authentication (CVE-ID: CVE-2026-53561)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to authenticate as an arbitrary Hive user and obtain an authenticated HiveServer2 session.
The vulnerability exists due to improper authentication in HiveServer2 SAML bearer-token validation when handling forged bearer tokens sent to the /cliservice HTTP endpoint. A remote attacker can send a forged authorization bearer token to authenticate as an arbitrary Hive user and obtain an authenticated HiveServer2 session.
The issue affects deployments using HTTP transport with SAML authentication enabled.
3) Input validation error (CVE-ID: CVE-2026-55976)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.
The vulnerability exists due to insufficient input validation in Hive Avro SerDe schema resolution when resolving the avro.schema.url table property on an Avro table that is subsequently queried. A remote user can create a crafted Avro table with a malicious avro.schema.url value to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.
Exploitation requires the ability to create a table, and external tables are typically required in practice.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=p4n6g74kyc4jfmr1d6hv321z3lcjxlgr
- https://github.com/apache/hive/commit/ca64f08a8e43db9845b47d5fa2e96f7fdea7288e
- https://lists.apache.org/api/email.lua?id=d4xogwnqx7zdk5csogotkj1fzorbm0jf
- https://github.com/apache/hive/commit/6ca06ca1104ff7462363087a867d70d546134774
- https://lists.apache.org/api/email.lua?id=ol0wvtdzmybqyg892v3p1p4sdbwk1oky
- https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00