CVE-2026-28672

CVE-2026-28672: Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder

Vendor Apache Software Foundation
Product Apache Ranger
Weakness CWE-77
Published August 10, 2026
Last update August 12, 2026

CVSS base score

What the vulnerability does

01Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.

Key dates

02Disclosure timeline

August 10, 2026 CVE published
August 12, 2026 Record updated

Related vulnerabilities

04Related CVE