Improper Authentication in Apache Hive - CVE-2026-53561

 

Improper Authentication in Apache Hive - CVE-2026-53561

Published: August 27, 2026


Vulnerability identifier: #VU145880
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53561
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to authenticate as an arbitrary Hive user and obtain an authenticated HiveServer2 session.

The vulnerability exists due to improper authentication in HiveServer2 SAML bearer-token validation when handling forged bearer tokens sent to the /cliservice HTTP endpoint. A remote attacker can send a forged authorization bearer token to authenticate as an arbitrary Hive user and obtain an authenticated HiveServer2 session.

The issue affects deployments using HTTP transport with SAML authentication enabled.


Affected software

Apache Hive

How to mitigate CVE-2026-53561

Install security update from vendor's website.

Apache Hive - update to 4.2.1

External References

Related Security Bulletins