PT-2026-81255 · Apache · Apache Hive

·

CVE-2026-53561

·

Published

2026-08-25

·

Updated

2026-08-27

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Hive versions 4.0.0 through 4.2.0
Description Improper authentication occurs during SAML bearer-token validation in HiveServer2 on deployments using HTTP transport with hive.server2.authentication=SAML. An unauthenticated network attacker can authenticate as an arbitrary Hive user and obtain an authenticated HiveServer2 session by sending a forged Authorization: Bearer token to the /cliservice HTTP endpoint. This exploit requires no Hive credentials, SAML Identity Provider (IdP) login, or knowledge of the server signing secret, requiring only network reachability to the HiveServer2 HTTP port.
Recommendations Upgrade to version 4.2.1.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53561

Affected Products

Apache Hive