← Vulnerability feed

Vulnerability record · CVE-2018-11778 · published 5 October 2018

CVE-2018-11778: Apache ranger out-of-bounds write vulnerability

Apache · Ranger

UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0

8.8 CVSS 3.0 High EPSS 4.0% · top 9.8% CWE-787 · Out-of-bounds write
8.8CVSS 3.0 base score, v2 6.5
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11778 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-32227Apache ranger sql injection vulnerabilitySQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the i…EPSS 0.69%9.8CVE-2026-40920Apache ranger improper input validation vulnerabilityPrivilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes…EPSS 0.73%9.8CVE-2026-42537Apache ranger improper input validation vulnerabilityRemote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.EPSS 1.3%9.8CVE-2026-44416Apache ranger code injection vulnerabilityRemote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra…EPSS 1.2%9.8CVE-2026-55799Apache ranger code injection vulnerabilityRemote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi…EPSS 1.2%9.8CVE-2026-28672Apache ranger command injection vulnerabilityImproper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger:…EPSS 2.6%9.8CVE-2025-59059Apache ranger code injection vulnerabilityRemote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to…EPSS 1.2%9.8CVE-2024-55532Apache ranger csv injection vulnerabilityImproper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade…EPSS 0.81%

Source: NIST National Vulnerability Database (record CVE-2018-11778), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.