AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-40920

CRITICAL · CVSS 9.8 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Apache Ranger versions up to 2.8.0 are vulnerable to a privilege escalation flaw that can be exploited through a URL parameter. This vulnerability could allow an attacker to gain elevated permissions, potentially compromising sensitive data and system integrity. Organizations using affected versions should prioritize upgrading to version 2.9.0 to mitigate this risk.

CVE
CVE-2026-40920
Severity
CRITICAL
CVSS
9.8
EPSS
0.51%
Apache

Original NVD Description

Privilege Escalation via URL ParameterĀ is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.