Apache Hive 4.x Critical Flaw Lets Attackers Impersonate Any User via Forged Token
Apache disclosed CVE-2026-53561 on August 25, 2026, a critical authentication bypass in HiveServer2 affecting Apache Hive versions 4.0.0 through 4.2.0. The vulnerability allows an unauthenticated attacker with network access to the HiveServer2 HTTP endpoint to forge a Bearer token and gain a session as any arbitrary Hive user. The flaw only affects deployments using HTTP transport with SAML authentication enabled, not the default Kerberos or LDAP configurations. Researcher Andrew Rukin of Arenadata discovered and reported the bypass, which is classified under CWE-287 improper authentication. Apache has released version 4.2.1, which patches this issue alongside a Metastore SQL injection flaw and an Avro SerDe SSRF vulnerability.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in