PatchSiren cyber security CVE debrief
CVE-2026-49845 Apache Software Foundation CVE debrief
CVE-2026-49845 is a SQL injection issue in Apache Hive that allows authenticated users to read, modify, or affect partition metadata via crafted partition names in metastore RPC requests when direct SQL is enabled. The issue is fixed in version 4.2.1. Defenders of Apache Hive deployments should assess exposure and prioritize upgrading to version 4.2.1 or later. The vulnerability impacts partition metadata, including statistics updates, truncation targets, and file-metadata cache operations.
- Vendor
- Apache Software Foundation
- Product
- Apache Hive
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-09-28
Who should care
Defenders of Apache Hive deployments, operators, platform administrators, vulnerability management teams, and security teams should assess exposure and prioritize upgrading to version 4.2.1 or later. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review.
Why it matters
CVE-2026-49845 is a SQL injection issue in Apache Hive that allows authenticated users to read, modify, or affect partition metadata. Defenders should prioritize upgrading to version 4.2.1 or later.
- Read, modify, or affect unintended partition metadata
- Statistics updates, truncation targets, and file-metadata cache operations may be affected
- Authenticated users with access to Hive Metastore APIs can perform this attack
- Upgrade to version 4.2.1 or later to fix the issue
Technical summary
The SQL injection issue in Apache Hive allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata. The issue is caused by client-supplied partition names being embedded into SQL using string concatenation instead of bind parameters. This can affect reads, stats updates, truncate targets, metadata-cache targets, and related operations when metastore.try.direct.sql is enabled. The issue is fixed in version 4.2.1. Users are recommended to upgrade to version 4.2.1 or later to fix the issue.
Defensive priority
Upgrade to version 4.2.1 or later to fix the SQL injection issue in Apache Hive.
Recommended defensive actions
- Upgrade to version 4.2.1 or later
- Restrict access to Hive Metastore APIs
- Monitor for suspicious activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details about the SQL injection issue in Apache Hive. The issue allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49845 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49845
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49845 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49845
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/apache/hive
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://github.com/apache/hive/commit/ca64f08a8e43db9845b47d5fa2e96f7fdea7288e
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://issues.apache.org/jira/browse/HIVE-29622
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/6d56mk501fp4f8cb5wvrpj2jwd9knt05
[email protected] - Mailing List, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.