Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-53561

Apache Hive: forged SAML bearer token gives a HiveServer2 session as any user

Technology

Apache Hive

CVSS Score

7.4 / 10.0

Affected Versions

Apache Hive 4.0.0 to 4.2.0

Upstream Fix

4.2.1

Published

August 25, 2026

OSSeva Coverage

Fixed upstream

Description

HiveServer2 in HTTP transport with hive.server2.authentication=SAML does not validate bearer tokens properly, so an unauthenticated attacker who can reach the /cliservice endpoint can obtain a session as any Hive user with a forged Authorization: Bearer header. Deployments where Knox handles SSO and HiveServer2 uses LDAP or Kerberos are not affected.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running Apache Hive 4.0.0 to 4.2.0, you need this patch. Book a discovery call to get covered.