AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-65945

MEDIUM · CVSS 6.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Apache Ranger versions up to 2.8.0 are vulnerable due to logging mechanisms that store replayable JWT tokens, potentially allowing unauthorized access to sensitive information. Organizations using affected versions should prioritize upgrading to version 2.9.0 to mitigate the risk of token replay attacks. This issue is particularly critical for environments handling sensitive data or requiring strict access controls.

CVE
CVE-2026-65945
Severity
MEDIUM
CVSS
6.5
EPSS
0.28%
Apache

Original NVD Description

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.