CVE-2026-65942

CVE-2026-65942: Apache Ranger: Clients accept TLS certificates issued for other hostnames

Vendor Apache Software Foundation
Product Apache Ranger
Weakness CWE-297
Published August 10, 2026
Last update August 10, 2026

CVSS base score

What the vulnerability does

01Description

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

Key dates

02Disclosure timeline

August 10, 2026 CVE published
August 10, 2026 Record updated