AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-28672

CRITICAL · CVSS 9.8 EPSS 1.98%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Apache Ranger versions 0.6 through 2.8 are vulnerable to a command injection flaw due to improper neutralization of special elements. This vulnerability could allow an attacker to execute arbitrary commands on the server, potentially leading to unauthorized access or data manipulation. Organizations using affected versions of Apache Ranger should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-28672
Severity
CRITICAL
CVSS
9.8
EPSS
1.98%
Apache

Original NVD Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.