Brute-Force Protection Flaw in Apache Ranger Affecting UnixAuth Feature
CVE-2026-65948

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 August 2026

What is CVE-2026-65948?

A weakness in the UnixAuth feature of Apache Ranger versions up to 2.8.0 allows for brute-force attack attempts, exposing user accounts to unauthorized access risks. It is advised that users refrain from utilizing UnixAuth in production environments without adequate protective measures. Users should promptly upgrade to version 2.9.0 to ensure enhanced security and mitigate the risk associated with this vulnerability.

Affected Version(s)

Apache Ranger 0 <= 2.8.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
.