CyberRota Analysis
AI-GeneratedApache Ranger versions up to 2.8.0 are vulnerable due to logging mechanisms that store replayable JWT tokens, potentially allowing unauthorized access to sensitive information. Organizations using affected versions should prioritize upgrading to version 2.9.0 to mitigate the risk of token replay attacks. This issue is particularly critical for environments handling sensitive data or requiring strict access controls.
CVE
CVE-2026-65945
Severity
MEDIUM
CVSS
6.5
EPSS
0.28%
Apache
Original NVD Description
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.