CVE-2026-53561: Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user

Published Aug 25, 2026
·
Updated

An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated network attacker to authenticate as an arbitrary Hive user and obtain an authenticated HiveServer2 session via a forged Authorization: Bearer token sent to the /cliservice HTTP endpoint. Users are recommended to upgrade to 4.2.1 version that includes the fix for this issue.

Access / authorization required: No Hive credentials, SAML IdP login, or knowledge of the server signing secret is required. The attacker only needs network reachability to the HiveServer2 HTTP port (typically /cliservice), directly or through a reverse proxy such as Apache Knox that forwards unauthenticated requests to HS2. The instance must have SAML authentication enabled in HTTP mode. Deployments where Knox handles SSO and HiveServer2 uses LDAP/Kerberos (not native SAML mode) are not affected by this specific issue.

Affected Software

1 affected component
Apache Hive>=4.0.0<=4.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Hive to a version that resolves this vulnerability.

    Fixed in 4.2.1

Event History

Aug 25, 2026
CVE Published
via MITRE·10:12 AM
Data Sourced
via MITRE·10:12 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are affected?

Affected deployments run Apache Hive 4.0.0 through 4.2.0, use HiveServer2 HTTP transport, and set hive.server2.authentication=SAML. The vulnerable endpoint is the HiveServer2 /cliservice HTTP endpoint.

2

What does an attacker need to exploit this issue?

An attacker needs only network reachability to the HiveServer2 HTTP port, either directly or through a reverse proxy that forwards unauthenticated requests to HiveServer2. No Hive credentials, SAML IdP login, or server signing secret are required.

3

Are deployments using Apache Knox affected?

A Knox deployment can be affected if it forwards unauthenticated requests to HiveServer2 running native SAML authentication in HTTP mode. Deployments where Knox performs SSO while HiveServer2 uses LDAP or Kerberos rather than native SAML mode are not affected by this specific issue.

4

What should administrators do?

Upgrade Apache Hive to version 4.2.1, which includes the fix. Until upgrading, restrict unauthenticated network access to the HiveServer2 HTTP endpoint and prevent reverse proxies from forwarding unauthenticated requests to it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203