Junglewise Threat Intelligence

CVE-2026-65948: Apache Ranger UnixAuth missing brute-force protection

CVE-2026-65948 · Severity: high · CVSS 7.3 · Published 2026-08-10

Technologies: Apache Ranger. Vendors: Apache.

Executive brief

Apache Ranger's UnixAuth authentication module lacks rate-limiting or account lockout mechanisms to prevent brute-force password attacks. An attacker can attempt unlimited login attempts to compromise user accounts. The vendor notes UnixAuth is not recommended for production use, but organizations relying on it remain at risk until patching to version 2.9.0.

Technical details

UnixAuth is an authentication plugin in Apache Ranger that lacks brute-force protection mechanisms. The vulnerability allows an attacker to perform unlimited authentication attempts against user accounts without rate limiting or temporary lockouts, enabling password cracking attacks. The issue affects Apache Ranger versions up to and including 2.8.0. UnixAuth is deprecated and not recommended for production deployments. Apache Ranger 2.9.0 includes a fix for this vulnerability.

Affected products

  • Apache Ranger <=2.8.0

Timeline

  • 2026-08-10: disclosed: CVE-2026-65948 published
  • 2026-08-10: patched: Fix available in Apache Ranger 2.9.0

References

Related threats