TLS Hostname Verification Issue in Apache Ranger by Apache
CVE-2026-65942

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 August 2026

What is CVE-2026-65942?

The Apache Ranger Client Code has a vulnerability that affects versions up to 2.8.0, where TLS hostname verification is improperly handled. This weakness may allow unauthorized attackers to exploit the system, undermining the security measures in place. To mitigate risks associated with this vulnerability, users are strongly advised to upgrade to version 2.9.0, where this issue has been addressed.

Affected Version(s)

Apache Ranger 0 <= 2.8.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
.