Executive brief
Apache Ranger is an open-source data governance and security framework that manages access policies for big data platforms. A remote code execution vulnerability in the GraalScriptEngineCreator component allows attackers to execute arbitrary code, potentially compromising the confidentiality, integrity, and availability of the entire data governance infrastructure and sensitive data it protects.
Technical details
A remote code execution vulnerability exists in the GraalScriptEngineCreator component of Apache Ranger versions up to 2.8.0. The vulnerability likely stems from unsafe script evaluation or deserialization, allowing attackers to achieve arbitrary code execution without requiring authentication or user interaction. The affected component processes dynamic scripts or policies, and the RCE can be triggered over the network. Apache has released version 2.9.0 which addresses this vulnerability.
Affected products
- Apache Ranger through 2.8.0
Timeline
- 2026-08-09: disclosed
- 2026-08-10: patched: Version 2.9.0 fixes this issue