Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-49845PATCHED
apache · hive

Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths

Description

SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updates, truncation targets, and file-metadata cache operations) via crafted partition names in metastore RPC requests when direct SQL is enabled (the default). Users are recommended to upgrade to version 4.2.1, which fixes this issue. Details about the issue: Several Hive Metastore RPCs resolve partitions by full partition name (PART_NAME) through direct-SQL helpers. In those paths, client-supplied partition names are embedded into SQL using string concatenation (DirectSqlUpdatePart.quoteString() → '...') instead of bind parameters. A partition name containing a single quote (and crafted SQL) can alter the generated WHERE clause so that lookups intended for one partition match additional rows. That can affect reads, stats updates, truncate targets, metadata-cache targets, and related operations when metastore.try.direct.sql is enabled (default: true). An authenticated or network-trusted caller with the ability to invoke Hive Metastore partition-name APIs against a target table (directly or via Hive/other clients), when direct SQL is enabled can perform this attack. Also, the impact is mainly within table & partition targeting (read/update/truncate/drop/cache the wrong partitions in a table they can reference), not arbitrary cross-database access via this bug alone.

Affected Products

VendorProductVersions
apachehive4.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmspsscert_advisory90%

References

  • https://github.com/apache/hive(product)
  • https://github.com/apache/hive/commit/ca64f08a8e43db9845b47d5fa2e96f7fdea7288e(patch)
  • https://issues.apache.org/jira/browse/HIVE-29622(issue-tracking)
  • https://lists.apache.org/thread/6d56mk501fp4f8cb5wvrpj2jwd9knt05(vendor-advisory)

Related News (2 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] IBM SPSS Analytic Server und SPSS Modeler: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB33d ago
CVE-2026-49845 | Apache Hive up to 4.2.0 Direct SQL Partition Resolution DirectSqlUpdatePart.quoteString sql injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://github.com/apache/hive/commit/ca64f08a8e43db9845b47d5fa2e96f7fdea7288ehttps://lists.apache.org/thread/6d56mk501fp4f8cb5wvrpj2jwd9knt05
CWECWE-94
PublishedAug 25, 2026
Trending Score27
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71290
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Trending: 45
HIGHCVE-2026-59878
Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Trending: 38
CRITICALCVE-2026-55976
Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url
Trending: 33
CRITICALCVE-2026-66713
Apache Axis2/Java: deserialization of untrusted Data
Trending: 20
CRITICALCVE-2026-59083EXP
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Trending: 19

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Sep 4, 2026