CVE-2016-0760: Apache Sentry

High severity, CVSS 8.8. EPSS: 3.3% chance of exploitation in the next 30 days.

Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) reflect, (2) reflect2, or (3) java_method Hive builtin functions.

Affected products

  • Apache Sentry: version 1.5.1 only; version 1.6.0 only

Published 2016-08-19. Last modified 2026-06-17.