Junglewise Threat Intelligence

CVE-2026-53561: Apache Hive HiveServer2 SAML bearer-token authentication bypass

CVE-2026-53561 · Severity: high · CVSS 7.4 · Published 2026-08-25

Vendors: Apache.

Executive brief

Apache Hive is a data warehouse software used to query and analyze large datasets in Hadoop clusters. HiveServer2 is the server component that accepts client connections via HTTP. A flaw in SAML bearer-token validation allows unauthenticated attackers to forge authentication tokens and gain arbitrary user access to the system without credentials, potentially exposing sensitive data and enabling unauthorized data manipulation.

Technical details

This is an improper authentication vulnerability in HiveServer2's SAML bearer-token validation mechanism. The vulnerability exists when HiveServer2 is configured to use HTTP transport with SAML authentication enabled. An unauthenticated network attacker can craft a forged Authorization: Bearer token and send it to the /cliservice HTTP endpoint to authenticate as an arbitrary Hive user without possessing valid SAML IdP credentials or knowledge of the server's signing secret. Attack requires only network reachability to HiveServer2's HTTP port (typically port 10000) and applies to deployments using native SAML mode on HTTP; LDAP/Kerberos and reverse proxy configurations like Knox with SSO are unaffected. Affected versions are 4.0.0 through 4.2.0 and later unreleased branches; the fix is available in version 4.2.1.

Affected products

  • Apache Hive 4.0.0 through 4.2.0 and later unreleased branches

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fix available in version 4.2.1

References