Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-49845
Apache Hive: SQL injection in metastore direct SQL partition-name lookups
Technology
Apache Hive
CVSS Score
9.8 / 10.0
Affected Versions
Apache Hive 4.0.0 to 4.2.0
Upstream Fix
4.2.1
Published
August 25, 2026
OSSeva Coverage
Fixed upstream
Description
Several Hive Metastore RPCs resolve partitions by full partition name through direct SQL helpers that concatenate the client-supplied name into SQL instead of binding it. A crafted partition name can widen the WHERE clause, so an authenticated caller of the metastore APIs can read, update statistics on, truncate or cache partitions it did not target. It applies when metastore.try.direct.sql is enabled, the default.
Is your Apache Hive deployment affected?
If you're running Apache Hive 4.0.0 to 4.2.0, you need this patch. Book a discovery call to get covered.