CVE-2026-52691
nicheSQL Injection in Apache Griffin Hive Metastore Module (unsupported, no fix planned)
The Apache Griffin Hive Metastore Module is vulnerable to SQL injection (CWE-89) caused by improper neutralization of special elements in SQL commands, affecting all versions of the product. An attacker with low privileges and network access to the module can trigger the flaw via crafted input, potentially reading, modifying, or corrupting metadata stored in the Hive Metastore database. Because the component is retired, there is no patched release, so every deployment of Griffin's Hive Metastore Module remains permanently vulnerable. Only organizations still running Apache Griffin — an unsupported data-quality service — are affected. No public proof-of-concept, KEV listing, or known in-the-wild exploitation has been reported, and the 0.3% EPSS score indicates low expected exploitation in the next 30 days.
What to do: No patched version exists, so restrict network access to the Griffin Hive Metastore instance to trusted users only (per the Apache advisory) and review whether it is exposed beyond trusted internal segments. Consider fronting the service with input-validation or WAF rules that block SQL injection patterns, and plan a migration to an alternative, maintained data-quality/metadata solution. Audit any remaining Griffin deployments for unusual metastore database queries.
| Apache Griffin Hive Metastore Module | all versions (project retired; no fix will be released) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. This issue affects Apache Griffin Hive Metastore Module: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.