CVE-2016-0735: Apache Ranger

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.

Affected products

  • Apache Ranger: version 0.5.0 only; version 0.5.1 only

Published 2016-04-11. Last modified 2026-06-17.