Junglewise Threat Intelligence

CVE-2026-32227: Apache Ranger SQL injection vulnerability

CVE-2026-32227 · Severity: critical · CVSS 9.8 · Published 2026-08-10

Technologies: Apache Ranger. Vendors: Apache.

Executive brief

Apache Ranger is a data security platform used to manage authorization and auditing policies across Hadoop and cloud data platforms. A SQL injection vulnerability in Ranger allows attackers to execute arbitrary SQL queries against the underlying database, potentially leading to unauthorized data access, modification, or deletion of sensitive authorization policies and audit logs.

Technical details

This is a SQL injection vulnerability in Apache Ranger affecting an unspecified component. The vulnerability allows attackers to inject malicious SQL commands, likely through user-supplied input that is not properly sanitized before being passed to database queries. The attack is network-accessible and does not require authentication or user interaction. Successful exploitation enables arbitrary SQL query execution, which can compromise data confidentiality and integrity. The vendor has released version 2.9.0 which contains a fix for this issue.

Affected products

  • Apache Ranger versions prior to 2.9.0

Timeline

  • 2026-08-10: disclosed

References

Related threats