CVE-2026-65948

CVE-2026-65948: Apache Ranger: UnixAuth lacks brute-force protection

Vendor Apache Software Foundation
Product Apache Ranger
Weakness CWE-307 · Brute force
Published August 10, 2026
Last update August 10, 2026

CVSS base score

What the vulnerability does

01Description

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue.

Key dates

02Disclosure timeline

August 10, 2026 CVE published
August 10, 2026 Record updated

Related vulnerabilities

04Related CVE