SQL Injection Vulnerability in Apache Griffin Hive Metastore Module
CVE-2026-52691

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
4 September 2026

What is CVE-2026-52691?

The Apache Griffin Hive Metastore Module contains a vulnerability that allows for improper neutralization of special elements in an SQL command, known as SQL Injection. This risk is particularly critical for users of the Hive Metastore Module, as the project has been retired and is no longer supported. Consequently, no official fixes will be released for this issue. Users are strongly advised to seek alternative solutions or limit access to the impacted instances to only trusted personnel.

Affected Version(s)

Apache Griffin Hive Metastore Module 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Firebasky ( https://github.com/firebasky )
.