CVE-2026-28672
org.apache.ranger:ranger: Improper Neutralization of Special Elements used in a Command ('Command Injection') (CVE-2026-28672)
Description
Metrics
Weakness classes (CWE)
CWE-77Class
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-08-17 18:48 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:* versions from (including) 0.6.0 up to (including) 2.8.0
- Reference Type: Apache Software Foundation: https://lists.apache.org/thread/99ysjqcmz950o3jgm6pqx1wb696onzq7 Types: Mailing List, Vendor Advisory
- Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/08/09/2 Types: Mailing List, Third Party Advisory
- New CVE Received2026-08-10 11:17 UTC· security@apache.org
- Affected: Apache Ranger
- Description: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.
- CWE: CWE-77
- Reference: https://lists.apache.org/thread/99ysjqcmz950o3jgm6pqx1wb696onzq7
- CVE Modified2026-08-10 11:17 UTC· af854a3a-2127-422b-91ae-364da2661108
- Reference: http://www.openwall.com/lists/oss-security/2026/08/09/2
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
maven
org.apache.ranger:ranger0.6.0
maven
org.apache.ranger:ranger0.6.1
maven
org.apache.ranger:ranger0.6.2
maven
org.apache.ranger:ranger0.6.3
maven
org.apache.ranger:ranger0.7.0
maven
org.apache.ranger:ranger0.7.1
maven
org.apache.ranger:ranger1.0.0
maven
org.apache.ranger:ranger1.1.0
maven
org.apache.ranger:ranger1.2.0
maven
org.apache.ranger:ranger2.0.0
maven
org.apache.ranger:ranger2.1.0
maven
org.apache.ranger:ranger2.2.0
maven
org.apache.ranger:ranger2.3.0
maven
org.apache.ranger:ranger2.4.0
maven
org.apache.ranger:ranger2.5.0
maven
org.apache.ranger:ranger2.6.0
maven
org.apache.ranger:ranger2.7.0
maven
org.apache.ranger:ranger2.8.0