Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-49845

Apache Hive: SQL injection in metastore direct SQL partition-name lookups

Technology

Apache Hive

CVSS Score

9.8 / 10.0

Affected Versions

Apache Hive 4.0.0 to 4.2.0

Upstream Fix

4.2.1

Published

August 25, 2026

OSSeva Coverage

Fixed upstream

Description

Several Hive Metastore RPCs resolve partitions by full partition name through direct SQL helpers that concatenate the client-supplied name into SQL instead of binding it. A crafted partition name can widen the WHERE clause, so an authenticated caller of the metastore APIs can read, update statistics on, truncate or cache partitions it did not target. It applies when metastore.try.direct.sql is enabled, the default.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running Apache Hive 4.0.0 to 4.2.0, you need this patch. Book a discovery call to get covered.