PT-2026-69428 · Apache · Apache Ranger
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Ranger versions prior to 2.9.0
Description
An issue allows for privilege escalation through the manipulation of a URL parameter.
Recommendations
Upgrade to version 2.9.0.
Exploit
Fix
LPE
Improper Privilege Management
Improper Authentication
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Ranger