Improper Restriction of Excessive Authentication Attempts in Apache Ranger - CVE-2026-65948
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to compromise accounts via brute-force attacks.
The vulnerability exists due to improper protection against excessive authentication attempts in UnixAuth when processing authentication requests. A remote user can send repeated authentication attempts to compromise accounts via brute-force attacks.
UnixAuth is involved.