Remote Code Execution in Apache Ranger by Apache
CVE-2026-55799

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 August 2026

What is CVE-2026-55799?

A vulnerability exists in the GraalScriptEngineCreator component of Apache Ranger, allowing for remote code execution. This issue affects versions up to 2.8.0, enabling attackers to execute arbitrary code on the server, potentially leading to unauthorized data access or system control. Users are strongly encouraged to upgrade to version 2.9.0 to mitigate this vulnerability.

Affected Version(s)

Apache Ranger 0 <= 2.8.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kippford Q. <k3ppf0r@gmail.com>
.