🔐 CVE Alert

CVE-2026-40920

UNKNOWN 0.0

Apache Ranger: Privilege Escalation via URL Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

CWE CWE-269 CWE-20 CWE-287
Vendor apache software foundation
Product apache ranger
Published Aug 10, 2026
Last Updated Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache ranger

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache ranger are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Ranger
0 ≤ 2.8.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/zh92fob9gqp196rvz3x9t0d2fnq9g27d openwall.com: http://www.openwall.com/lists/oss-security/2026/08/09/4

Credits

Andrew Rukin (Arenadata)