Junglewise Threat Intelligence

CVE-2026-65942: Apache Ranger TLS hostname verification bypass

CVE-2026-65942 · Severity: high · CVSS 7.5 · Published 2026-08-10

Technologies: Apache Ranger. Vendors: Apache.

Executive brief

Apache Ranger is an open-source framework for managing access control and data protection across Hadoop and cloud platforms. A flaw in the client code fails to properly verify TLS certificate hostnames, allowing attackers on the network path to intercept and decrypt encrypted communications by presenting certificates for different hostnames. This could expose sensitive data in transit and enable account compromise.

Technical details

The vulnerability is a TLS hostname verification issue in Apache Ranger client code versions 2.8.0 and earlier. The client fails to validate that a server's TLS certificate is issued for the hostname being accessed, enabling man-in-the-middle (MITM) attacks on network-adjacent positions. An attacker can present a valid certificate issued to any hostname to intercept client-to-server communication, decrypt sensitive data, and potentially modify requests. The flaw is present in client implementations; no authentication bypass is required. A fix is available in version 2.9.0.

Affected products

  • Apache Ranger <= 2.8.0

Timeline

  • 2026-08-09: disclosed
  • 2026-08-10: patched: Fix available in version 2.9.0

References

Related threats