CVE-2026-28672: Apache Ranger

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.

Affected products

  • Apache Ranger: from 0.6.0, up to and including 2.8.0

Published 2026-08-10. Last modified 2026-08-17.