Executive brief
Apache Ranger's UnixAuth authentication module lacks rate-limiting or account lockout mechanisms to prevent brute-force password attacks. An attacker can attempt unlimited login attempts to compromise user accounts. The vendor notes UnixAuth is not recommended for production use, but organizations relying on it remain at risk until patching to version 2.9.0.
Technical details
UnixAuth is an authentication plugin in Apache Ranger that lacks brute-force protection mechanisms. The vulnerability allows an attacker to perform unlimited authentication attempts against user accounts without rate limiting or temporary lockouts, enabling password cracking attacks. The issue affects Apache Ranger versions up to and including 2.8.0. UnixAuth is deprecated and not recommended for production deployments. Apache Ranger 2.9.0 includes a fix for this vulnerability.
Affected products
- Apache Ranger <=2.8.0
Timeline
- 2026-08-10: disclosed: CVE-2026-65948 published
- 2026-08-10: patched: Fix available in Apache Ranger 2.9.0