Technology · Apache
Apache Ranger vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 12 vulnerabilities in Apache Ranger: 0 in the last 7 days and 10 in the last 90 days, 7 of them critical and 0 exploited in the wild. The most recent, CVE-2026-65948, was published on 10 August 2026.
- Last 7 days
- 0
- Last 90 days
- 10
- Critical, all time
- 7
- Exploited in the wild
- 0
About Apache Ranger
Apache project for centralized security and authorization administration across Hadoop and other big data platforms.
Latest Apache Ranger vulnerabilities
- CVE-2026-65948: Apache Ranger UnixAuth missing brute-force protectionhighCVSS 7.3EPSS 0.6%
- CVE-2026-65945: Apache Ranger JWT token exposure in logsmediumCVSS 6.5EPSS 0.6%
- CVE-2026-65942: Apache Ranger TLS hostname verification bypasshighCVSS 7.5EPSS 0.6%
- CVE-2026-55814: Apache Ranger missing authentication in Download APIshighCVSS 7.5EPSS 0.7%
- CVE-2026-55799: Apache Ranger remote code execution in GraalScriptEngineCreatorcriticalCVSS 9.8EPSS 1.2%
- CVE-2026-44416: Apache Ranger remote code execution via arbitrary class instantiation in plugin-schema-registrycriticalCVSS 9.8EPSS 1.2%
- CVE-2026-42537: Apache Ranger remote code execution via JDBC URL injectioncriticalCVSS 9.8EPSS 1.3%
- CVE-2026-40920: Apache Ranger privilege escalation via URL parametercriticalCVSS 9.8EPSS 0.7%
- CVE-2026-32227: Apache Ranger SQL injection vulnerabilitycriticalCVSS 9.8EPSS 0.7%
- CVE-2026-28672: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This…criticalCVSS 9.8EPSS 2.6%
- CVE-2025-59060: Apache Ranger NiFiRegistryClient hostname verification bypassmediumCVSS 5.3EPSS 0.3%
- CVE-2024-45479: Apache Ranger UI server-side request forgery in Edit Service PagecriticalCVSS 9.1EPSS 0.6%
Most severe Apache Ranger vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-28672: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This…criticalCVSS 9.8EPSS 2.6%
- CVE-2026-42537: Apache Ranger remote code execution via JDBC URL injectioncriticalCVSS 9.8EPSS 1.3%
- CVE-2026-44416: Apache Ranger remote code execution via arbitrary class instantiation in plugin-schema-registrycriticalCVSS 9.8EPSS 1.2%
- CVE-2026-55799: Apache Ranger remote code execution in GraalScriptEngineCreatorcriticalCVSS 9.8EPSS 1.2%
- CVE-2026-40920: Apache Ranger privilege escalation via URL parametercriticalCVSS 9.8EPSS 0.7%
- CVE-2026-32227: Apache Ranger SQL injection vulnerabilitycriticalCVSS 9.8EPSS 0.7%
- CVE-2024-45479: Apache Ranger UI server-side request forgery in Edit Service PagecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-55814: Apache Ranger missing authentication in Download APIshighCVSS 7.5EPSS 0.7%
- CVE-2026-65942: Apache Ranger TLS hostname verification bypasshighCVSS 7.5EPSS 0.6%
- CVE-2026-65948: Apache Ranger UnixAuth missing brute-force protectionhighCVSS 7.3EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 10 | 6 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/ranger.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apache Ranger vulnerabilities", https://junglewise.ai/threats/technologies/ranger, 26 September 2026.