{"schema_version":1,"title":"Apache Ranger vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in Apache Ranger: 0 in the last 7 days and 10 in the last 90 days, 7 of them critical and 0 exploited in the wild. The most recent, CVE-2026-65948, was published on 10 August 2026.","url":"https://junglewise.ai/threats/technologies/ranger","json_url":"https://junglewise.ai/threats/technologies/ranger.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/ranger","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":12,"critical":7,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":10,"last_365_days":11},"latest":[{"cve":"CVE-2026-65948","cvss":7.3,"epss":0.0062,"slug":"cve-2026-65948-apache-ranger-unixauth-missing-brute-force-protection","title":"Apache Ranger UnixAuth missing brute-force protection","severity":"high","exploited":false,"published_at":"2026-08-10T11:17:27.483+00:00","url":"https://junglewise.ai/threats/cve-2026-65948-apache-ranger-unixauth-missing-brute-force-protection"},{"cve":"CVE-2026-65945","cvss":6.5,"epss":0.0064,"slug":"cve-2026-65945-apache-ranger-jwt-token-exposure-in-logs","title":"Apache Ranger JWT token exposure in logs","severity":"medium","exploited":false,"published_at":"2026-08-10T11:17:27.363+00:00","url":"https://junglewise.ai/threats/cve-2026-65945-apache-ranger-jwt-token-exposure-in-logs"},{"cve":"CVE-2026-65942","cvss":7.5,"epss":0.0059,"slug":"cve-2026-65942-apache-ranger-tls-hostname-verification-bypass","title":"Apache Ranger TLS hostname verification bypass","severity":"high","exploited":false,"published_at":"2026-08-10T11:17:27.24+00:00","url":"https://junglewise.ai/threats/cve-2026-65942-apache-ranger-tls-hostname-verification-bypass"},{"cve":"CVE-2026-55814","cvss":7.5,"epss":0.0066,"slug":"cve-2026-55814-apache-ranger-missing-authentication-in-download-apis","title":"Apache Ranger missing authentication in Download APIs","severity":"high","exploited":false,"published_at":"2026-08-10T11:17:26.79+00:00","url":"https://junglewise.ai/threats/cve-2026-55814-apache-ranger-missing-authentication-in-download-apis"},{"cve":"CVE-2026-55799","cvss":9.8,"epss":0.0122,"slug":"cve-2026-55799-apache-ranger-remote-code-execution-in-graalscriptenginecreator","title":"Apache Ranger remote code execution in GraalScriptEngineCreator","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.67+00:00","url":"https://junglewise.ai/threats/cve-2026-55799-apache-ranger-remote-code-execution-in-graalscriptenginecreator"},{"cve":"CVE-2026-44416","cvss":9.8,"epss":0.0124,"slug":"cve-2026-44416-apache-ranger-remote-code-execution-via-arbitrary-class","title":"Apache Ranger remote code execution via arbitrary class instantiation in plugin-schema-registry","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.547+00:00","url":"https://junglewise.ai/threats/cve-2026-44416-apache-ranger-remote-code-execution-via-arbitrary-class"},{"cve":"CVE-2026-42537","cvss":9.8,"epss":0.0129,"slug":"cve-2026-42537-apache-ranger-remote-code-execution-via-jdbc-url-injection","title":"Apache Ranger remote code execution via JDBC URL injection","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.42+00:00","url":"https://junglewise.ai/threats/cve-2026-42537-apache-ranger-remote-code-execution-via-jdbc-url-injection"},{"cve":"CVE-2026-40920","cvss":9.8,"epss":0.0073,"slug":"cve-2026-40920-apache-ranger-privilege-escalation-via-url-parameter","title":"Apache Ranger privilege escalation via URL parameter","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.287+00:00","url":"https://junglewise.ai/threats/cve-2026-40920-apache-ranger-privilege-escalation-via-url-parameter"},{"cve":"CVE-2026-32227","cvss":9.8,"epss":0.0069,"slug":"cve-2026-32227-apache-ranger-sql-injection-vulnerability","title":"Apache Ranger SQL injection vulnerability","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.16+00:00","url":"https://junglewise.ai/threats/cve-2026-32227-apache-ranger-sql-injection-vulnerability"},{"cve":"CVE-2026-28672","cvss":9.8,"epss":0.0263,"slug":"cve-2026-28672-apache-ranger-command-injection-vulnerability","title":"Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apac","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:25.19+00:00","url":"https://junglewise.ai/threats/cve-2026-28672-apache-ranger-command-injection-vulnerability"},{"cve":"CVE-2025-59060","cvss":5.3,"epss":0.0033,"slug":"cve-2025-59060-apache-ranger-nifiregistryclient-hostname-verification-bypass","title":"Apache Ranger NiFiRegistryClient hostname verification bypass","severity":"medium","exploited":false,"published_at":"2026-03-03T11:16:14.853+00:00","url":"https://junglewise.ai/threats/cve-2025-59060-apache-ranger-nifiregistryclient-hostname-verification-bypass"},{"cve":"CVE-2024-45479","cvss":9.1,"epss":0.0064,"slug":"cve-2024-45479-apache-ranger-ui-server-side-request-forgery-in-edit-service-page","title":"Apache Ranger UI server-side request forgery in Edit Service Page","severity":"critical","exploited":false,"published_at":"2025-01-22T00:33:36+00:00","url":"https://junglewise.ai/threats/cve-2024-45479-apache-ranger-ui-server-side-request-forgery-in-edit-service-page"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":6,"exploited":0,"vulnerabilities":10},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Apache Airflow","slug":"airflow","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache HTTP Server","slug":"http-server","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/http-server"},{"name":"Apache CloudStack","slug":"cloudstack","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache Thrift","slug":"thrift","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/thrift"},{"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/activemq-artemis"}],"technology":{"hub":true,"name":"Apache Ranger","slug":"ranger","vendor":{"name":"Apache","slug":"apache","url":"https://junglewise.ai/threats/vendors/apache"},"aliases":[],"category":"framework","homepage":"https://ranger.apache.org/","description":"Apache project for centralized security and authorization administration across Hadoop and other big data platforms.","url":"https://junglewise.ai/threats/technologies/ranger"},"most_severe":[{"cve":"CVE-2026-28672","cvss":9.8,"epss":0.0263,"slug":"cve-2026-28672-apache-ranger-command-injection-vulnerability","title":"Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apac","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:25.19+00:00","url":"https://junglewise.ai/threats/cve-2026-28672-apache-ranger-command-injection-vulnerability"},{"cve":"CVE-2026-42537","cvss":9.8,"epss":0.0129,"slug":"cve-2026-42537-apache-ranger-remote-code-execution-via-jdbc-url-injection","title":"Apache Ranger remote code execution via JDBC URL injection","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.42+00:00","url":"https://junglewise.ai/threats/cve-2026-42537-apache-ranger-remote-code-execution-via-jdbc-url-injection"},{"cve":"CVE-2026-44416","cvss":9.8,"epss":0.0124,"slug":"cve-2026-44416-apache-ranger-remote-code-execution-via-arbitrary-class","title":"Apache Ranger remote code execution via arbitrary class instantiation in plugin-schema-registry","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.547+00:00","url":"https://junglewise.ai/threats/cve-2026-44416-apache-ranger-remote-code-execution-via-arbitrary-class"},{"cve":"CVE-2026-55799","cvss":9.8,"epss":0.0122,"slug":"cve-2026-55799-apache-ranger-remote-code-execution-in-graalscriptenginecreator","title":"Apache Ranger remote code execution in GraalScriptEngineCreator","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.67+00:00","url":"https://junglewise.ai/threats/cve-2026-55799-apache-ranger-remote-code-execution-in-graalscriptenginecreator"},{"cve":"CVE-2026-40920","cvss":9.8,"epss":0.0073,"slug":"cve-2026-40920-apache-ranger-privilege-escalation-via-url-parameter","title":"Apache Ranger privilege escalation via URL parameter","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.287+00:00","url":"https://junglewise.ai/threats/cve-2026-40920-apache-ranger-privilege-escalation-via-url-parameter"},{"cve":"CVE-2026-32227","cvss":9.8,"epss":0.0069,"slug":"cve-2026-32227-apache-ranger-sql-injection-vulnerability","title":"Apache Ranger SQL injection vulnerability","severity":"critical","exploited":false,"published_at":"2026-08-10T11:17:26.16+00:00","url":"https://junglewise.ai/threats/cve-2026-32227-apache-ranger-sql-injection-vulnerability"},{"cve":"CVE-2024-45479","cvss":9.1,"epss":0.0064,"slug":"cve-2024-45479-apache-ranger-ui-server-side-request-forgery-in-edit-service-page","title":"Apache Ranger UI server-side request forgery in Edit Service Page","severity":"critical","exploited":false,"published_at":"2025-01-22T00:33:36+00:00","url":"https://junglewise.ai/threats/cve-2024-45479-apache-ranger-ui-server-side-request-forgery-in-edit-service-page"},{"cve":"CVE-2026-55814","cvss":7.5,"epss":0.0066,"slug":"cve-2026-55814-apache-ranger-missing-authentication-in-download-apis","title":"Apache Ranger missing authentication in Download APIs","severity":"high","exploited":false,"published_at":"2026-08-10T11:17:26.79+00:00","url":"https://junglewise.ai/threats/cve-2026-55814-apache-ranger-missing-authentication-in-download-apis"},{"cve":"CVE-2026-65942","cvss":7.5,"epss":0.0059,"slug":"cve-2026-65942-apache-ranger-tls-hostname-verification-bypass","title":"Apache Ranger TLS hostname verification bypass","severity":"high","exploited":false,"published_at":"2026-08-10T11:17:27.24+00:00","url":"https://junglewise.ai/threats/cve-2026-65942-apache-ranger-tls-hostname-verification-bypass"},{"cve":"CVE-2026-65948","cvss":7.3,"epss":0.0062,"slug":"cve-2026-65948-apache-ranger-unixauth-missing-brute-force-protection","title":"Apache Ranger UnixAuth missing brute-force protection","severity":"high","exploited":false,"published_at":"2026-08-10T11:17:27.483+00:00","url":"https://junglewise.ai/threats/cve-2026-65948-apache-ranger-unixauth-missing-brute-force-protection"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}