Junglewise Threat Intelligence

CVE-2026-65945: Apache Ranger JWT token exposure in logs

CVE-2026-65945 · Severity: medium · CVSS 6.5 · Published 2026-08-10

Technologies: Apache Ranger. Vendors: Apache.

Executive brief

Apache Ranger is an access control framework used to manage permissions and security policies across data platforms. This vulnerability allows JWT tokens stored in application logs to be reused by attackers to impersonate users and bypass authentication, potentially granting unauthorized access to sensitive data and administrative functions.

Technical details

The vulnerability is a credential exposure issue where JWT bearer tokens are logged in plaintext within Apache Ranger's application logs in versions up to 2.8.0. These tokens can be replayed by an attacker who gains access to the logs (via file system access, log aggregation systems, or other log exposure vectors) to authenticate as the legitimate user without knowledge of their password. The attack requires either local or remote access to logs but does not require network access to actively exploit if logs are exfiltrated. The fix is available in Apache Ranger 2.9.0, which prevents JWT tokens from being logged.

Affected products

  • Apache Ranger 2.8.0 and earlier

Timeline

  • 2026-08-09: disclosed
  • 2026-08-10: advisory
  • 2026: patched: Fix available in Apache Ranger 2.9.0

References

Related threats