Executive brief
Apache Ranger is an open-source platform for managing data security and governance policies across Hadoop and related systems. A privilege escalation vulnerability in versions 2.8.0 and earlier allows attackers to gain elevated access by manipulating URL parameters, potentially enabling unauthorized administrative actions or data access. Organizations using affected versions should upgrade immediately to patch the security hole.
Technical details
A privilege escalation vulnerability exists in Apache Ranger through version 2.8.0, exploitable via URL parameter manipulation. The vulnerability allows an authenticated or unauthenticated attacker to bypass authorization controls and escalate privileges on the platform. Attack vectors and specific preconditions are not detailed in the advisory, but the critical CVSS score (9.8) suggests significant exploitability with low complexity. The vulnerability is fixed in version 2.9.0; affected users should upgrade immediately.
Affected products
- Apache Ranger through 2.8.0
Timeline
- 2026-08-09: disclosed
- 2026-08-10: published
- 2026: patched: Fixed in version 2.9.0