Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-53561
Apache Hive: forged SAML bearer token gives a HiveServer2 session as any user
Technology
Apache Hive
CVSS Score
7.4 / 10.0
Affected Versions
Apache Hive 4.0.0 to 4.2.0
Upstream Fix
4.2.1
Published
August 25, 2026
OSSeva Coverage
Fixed upstream
Description
HiveServer2 in HTTP transport with hive.server2.authentication=SAML does not validate bearer tokens properly, so an unauthenticated attacker who can reach the /cliservice endpoint can obtain a session as any Hive user with a forged Authorization: Bearer header. Deployments where Knox handles SSO and HiveServer2 uses LDAP or Kerberos are not affected.
Is your Apache Hive deployment affected?
If you're running Apache Hive 4.0.0 to 4.2.0, you need this patch. Book a discovery call to get covered.