Skip to content

Apache Hive: improper authentication

High7.4CVE-2026-53561 · Published Aug 25, 2026 · updated Sep 28, 2026

An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated network attacker to authenticate as an arbitrary Hive user and obtain an authenticated HiveServer2 session via a forged Authorization: Bearer token sent to the /cliservice HTTP endpoint. Users are recommended to upgrade to 4.2.1 version that includes the fix for this issue. Access / authorization required: No Hive credentials, SAML IdP login, or knowledge of the server signing secret is required. The attacker only needs network reachability to the HiveServer2 HTTP port (typically /cliservice), directly or through a reverse proxy such as Apache Knox that forwards unauthenticated requests to HS2. The instance must have SAML authentication enabled in HTTP mode. Deployments where Knox handles SSO and HiveServer2 uses LDAP/Kerberos (not native SAML mode) are not affected by this specific issue.

Affected versions

PackageAffectedFixed in
Apache Hive
Product
>= 4.0.0, <= 4.2.0No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Hive: SQL injection
Critical9.8Aug 25
Apache Hive: server-side request forgery
Critical9.1Aug 25
Apache DolphinScheduler: improper authorization
High8.8Aug 25
APR-util versions 1.6.3
High7.5Aug 6
Apache Traffic Server: out-of-bounds write
High8.4Jul 29
Apache Traffic Server: server-side request forgery
High8.2Jul 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.