Improper Authentication in Apache Hive's SAML Bearer-Token Validation
CVE-2026-53561

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
25 August 2026

What is CVE-2026-53561?

An improper authentication vulnerability in the SAML bearer-token validation of Apache Hive versions 4.0.0 to 4.2.0 exposes deployments using HTTP transport with 'hive.server2.authentication=SAML'. This flaw allows an unauthenticated network attacker to impersonate any Hive user and establish an authenticated session with HiveServer2 by sending a forged Authorization: Bearer token to the /cliservice HTTP endpoint. Importantly, the attacker can execute this attack without possessing any Hive credentials, SAML IdP login, or knowledge of the server's signing secret. It is crucial to upgrade to Apache Hive version 4.2.1 to mitigate this vulnerability. Deployments utilizing reverse proxies like Apache Knox that do not forward unauthenticated requests to HiveServer2 or where SSO is handled differently, such as through LDAP/Kerberos, remain unaffected.

Affected Version(s)

Apache Hive 4.0.0 <= 4.2.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
.