Technology · Maven
org.apache.ranger:ranger (Maven) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 17 vulnerabilities in org.apache.ranger:ranger (Maven): 0 in the last 7 days and 1 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-28672, was published on 10 August 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 2
- Exploited in the wild
- 0
About org.apache.ranger:ranger (Maven)
Apache framework for centralized security services and data governance.
Latest org.apache.ranger:ranger (Maven) vulnerabilities
- CVE-2026-28672: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This…criticalCVSS 9.8EPSS 2.6%
- CVE-2024-45479: Apache Ranger UI server-side request forgery in Edit Service PagecriticalCVSS 9.1EPSS 0.6%
- CVE-2024-45478: Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service PagelowCVSS 3.1EPSS 0.6%
- CVE-2022-45048: Apache Ranger code execution vulnerability in policy expressionslowCVSS 3.1EPSS 1.1%
- CVE-2015-0265: Apache Ranger Cross-site Scripting vulnerabilitylowCVSS 3EPSS 4.9%
- CVE-2015-0266: Apache Ranger allows users to bypass intended access restrictions via direct access to module URLslowCVSS 3EPSS 2.1%
- CVE-2015-5167: Apache Ranger allows users to bypass intended access restrictions via the REST APIlowCVSS 3EPSS 1.9%
- CVE-2016-0735: Apache Ranger Access Restriction BypasslowCVSS 3EPSS 1.7%
- CVE-2019-12397: Cross-site scripting in Apache RangerlowCVSS 3EPSS 3.0%
- CVE-2017-7677: Moderate severity vulnerability that affects org.apache.ranger:rangerlowCVSS 3EPSS 2.6%
- CVE-2017-7676: Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '' wildcard characterlowCVSS 3EPSS 4.2%
- CVE-2018-11778: UnixAuthenticationService in Apache Ranger was updated to correctly handle user input to avoid Stack-based buffer overflowlowCVSS 3EPSS 4.0%
- CVE-2016-8751: Apache Ranger admin users can store some arbitrary javascript code to be executed when normal users login and access policieslowCVSS 3EPSS 2.1%
- CVE-2016-6815: Moderate severity vulnerability that affects org.apache.ranger:rangerlowCVSS 3EPSS 2.1%
- CVE-2016-5395: Apache Ranger allows remote authenticated administrators to inject arbitrary web script or HTMLlowCVSS 3EPSS 2.1%
- CVE-2016-2174: SQL injection vulnerability in the policy admin tool in Apache RangerlowCVSS 3EPSS 1.9%
- CVE-2016-0733: The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a passwordlowCVSS 3EPSS 3.1%
Most severe org.apache.ranger:ranger (Maven) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-28672: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This…criticalCVSS 9.8EPSS 2.6%
- CVE-2024-45479: Apache Ranger UI server-side request forgery in Edit Service PagecriticalCVSS 9.1EPSS 0.6%
- CVE-2022-45048: Apache Ranger code execution vulnerability in policy expressionslowCVSS 3.1EPSS 1.1%
- CVE-2024-45478: Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service PagelowCVSS 3.1EPSS 0.6%
- CVE-2015-0265: Apache Ranger Cross-site Scripting vulnerabilitylowCVSS 3EPSS 4.9%
- CVE-2017-7676: Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '' wildcard characterlowCVSS 3EPSS 4.2%
- CVE-2018-11778: UnixAuthenticationService in Apache Ranger was updated to correctly handle user input to avoid Stack-based buffer overflowlowCVSS 3EPSS 4.0%
- CVE-2016-0733: The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a passwordlowCVSS 3EPSS 3.1%
- CVE-2019-12397: Cross-site scripting in Apache RangerlowCVSS 3EPSS 3.0%
- CVE-2017-7677: Moderate severity vulnerability that affects org.apache.ranger:rangerlowCVSS 3EPSS 2.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 1 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/org-apache-ranger-ranger.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "org.apache.ranger:ranger (Maven) vulnerabilities", https://junglewise.ai/threats/technologies/org-apache-ranger-ranger, 28 September 2026.