AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-65948

HIGH · CVSS 7.3 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache Ranger versions up to 2.8.0 are vulnerable due to the lack of brute-force protection in the UnixAuth authentication method, which is not advised for production use. This vulnerability could allow attackers to exploit weak password policies and gain unauthorized access. Organizations using Apache Ranger should prioritize upgrading to version 2.9.0 to mitigate this risk.

CVE
CVE-2026-65948
Severity
HIGH
CVSS
7.3
EPSS
0.30%
Apache

Original NVD Description

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue.