Known vulnerabilities in Apache Ranger

Software: Apache Ranger
Software CPE: cpe:2.3:a:apache_foundation:apache_ranger:*:*:*:*:*:*:*:*
Total vulnerabilities: 10
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Ranger Apache Ranger is affected by 10 known vulnerabilities: 3 high, 5 medium, 2 low Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144936 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-32227
CWE-89 Medium
No
No
2.9.0 24.08.2026 SB20260824186
#VU144915 - Improper Restriction of Excessive Authentication Attempts
CVE-2026-65948
CWE-307 Low
No
No
2.9.0 24.08.2026 SB20260824186
#VU144914 - Information Exposure Through Log Files
CVE-2026-65945
CWE-532 Medium
No
No
2.9.0 24.08.2026 SB20260824186
#VU144913 - Improper Validation of Certificate with Host Mismatch
CVE-2026-65942
CWE-297 Medium
No
No
2.9.0 24.08.2026 SB20260824186
#VU144912 - Missing Authentication for Critical Function
CVE-2026-55814
CWE-306 Medium
No
No
2.9.0 24.08.2026 SB20260824186
#VU144911 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-55799
CWE-94 High
No
No
2.9.0 24.08.2026 SB20260824186
#VU144909 - Improper Control of Dynamically-Managed Code Resources
CVE-2026-44416
CWE-913 High
No
No
2.9.0 24.08.2026 SB20260824186
#VU144908 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-42537
CWE-74 High
No
No
2.9.0 24.08.2026 SB20260824186
#VU144907 - Improper Access Control
CVE-2026-40920
CWE-284 Low
No
No
2.9.0 24.08.2026 SB20260824186
#VU144906 - Command injection
CVE-2026-28672
CWE-77 Medium
No
No
2.9.0 24.08.2026 SB20260824186