← Vulnerability feed

Vulnerability record · CVE-2026-65948 · published 10 August 2026

CVE-2026-65948: Apache ranger improper restriction of authentication attempts vulnerability

Apache · Ranger

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue.

7.3 CVSS 3.1 High EPSS 0.62% · top 52.5% CWE-307 · Improper restriction of authentication attempts
7.3CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Aug 2026Last modified by NVD

Description

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-65948 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-32227Apache ranger sql injection vulnerabilitySQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the i…EPSS 0.69%9.8CVE-2026-40920Apache ranger improper input validation vulnerabilityPrivilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes…EPSS 0.73%9.8CVE-2026-42537Apache ranger improper input validation vulnerabilityRemote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.EPSS 1.3%9.8CVE-2026-44416Apache ranger code injection vulnerabilityRemote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra…EPSS 1.2%9.8CVE-2026-55799Apache ranger code injection vulnerabilityRemote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi…EPSS 1.2%9.8CVE-2026-28672Apache ranger command injection vulnerabilityImproper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger:…EPSS 2.6%9.8CVE-2025-59059Apache ranger code injection vulnerabilityRemote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to…EPSS 1.2%9.8CVE-2024-55532Apache ranger csv injection vulnerabilityImproper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade…EPSS 0.81%

Source: NIST National Vulnerability Database (record CVE-2026-65948), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.