SQL Injection in Apache Hive Metastore Affects Partition Metadata
CVE-2026-49845
Currently unrated
What is CVE-2026-49845?
A vulnerability exists in the Hive Metastore that allows authenticated users to exploit SQL injection through direct SQL partition-name resolution. This occurs in versions of Apache Hive before 4.2.1 and affects how partitions are resolved by embedding user-supplied partition names into SQL queries without using bind parameters. Maliciously crafted partition names can manipulate the WHERE clause, leading to unintended access to partition metadata and affecting operations like reading, updating, and truncating partitions. Users are strongly advised to upgrade to version 4.2.1 to eliminate this security risk.
Affected Version(s)
Apache Hive 4.0.0 <= 4.2.0