CVE-2026-28672

org.apache.ranger:ranger: Improper Neutralization of Special Elements used in a Command ('Command Injection') (CVE-2026-28672)

criticalPoCEPSS 1.3%

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.

Metrics

Severity
critical
PoC (publicly reported)
9.8
Source: cna-v3
69.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
1.3 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-10 10:26 UTC
CWE-77

Weakness classes (CWE)

  • CWE-77Class

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

    The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-08-17 18:48 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:* versions from (including) 0.6.0 up to (including) 2.8.0
    • Reference Type: Apache Software Foundation: https://lists.apache.org/thread/99ysjqcmz950o3jgm6pqx1wb696onzq7 Types: Mailing List, Vendor Advisory
    • Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/08/09/2 Types: Mailing List, Third Party Advisory
  2. New CVE Received2026-08-10 11:17 UTC· security@apache.org
    • Affected: Apache Ranger
    • Description: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.
    • CWE: CWE-77
    • Reference: https://lists.apache.org/thread/99ysjqcmz950o3jgm6pqx1wb696onzq7
  3. CVE Modified2026-08-10 11:17 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/08/09/2

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • maven

    org.apache.ranger:ranger0.6.0

  • maven

    org.apache.ranger:ranger0.6.1

  • maven

    org.apache.ranger:ranger0.6.2

  • maven

    org.apache.ranger:ranger0.6.3

  • maven

    org.apache.ranger:ranger0.7.0

  • maven

    org.apache.ranger:ranger0.7.1

  • maven

    org.apache.ranger:ranger1.0.0

  • maven

    org.apache.ranger:ranger1.1.0

  • maven

    org.apache.ranger:ranger1.2.0

  • maven

    org.apache.ranger:ranger2.0.0

  • maven

    org.apache.ranger:ranger2.1.0

  • maven

    org.apache.ranger:ranger2.2.0

  • maven

    org.apache.ranger:ranger2.3.0

  • maven

    org.apache.ranger:ranger2.4.0

  • maven

    org.apache.ranger:ranger2.5.0

  • maven

    org.apache.ranger:ranger2.6.0

  • maven

    org.apache.ranger:ranger2.7.0

  • maven

    org.apache.ranger:ranger2.8.0

References & sources

IDCVE-2026-28672