CVE-2026-49845 | Apache Hive up to 4.2.0 Direct SQL Partition Resolution DirectSqlUpdatePart.quoteString sql injection
A vulnerability was found in Apache Hive up to 4.2.0. It has been declared as critical. This vulnerability affects the function DirectSqlUpdatePart.quoteString of the component Direct SQL Partition Resolution. Executing a manipulation can lead to sql injection.
This vulnerability is tracked as CVE-2026-49845. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More