Brute-Force Protection Flaw in Apache Ranger Affecting UnixAuth Feature
CVE-2026-65948

7.3HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 August 2026

What is CVE-2026-65948?

A weakness in the UnixAuth feature of Apache Ranger versions up to 2.8.0 allows for brute-force attack attempts, exposing user accounts to unauthorized access risks. It is advised that users refrain from utilizing UnixAuth in production environments without adequate protective measures. Users should promptly upgrade to version 2.9.0 to ensure enhanced security and mitigate the risk associated with this vulnerability.

Affected Version(s)

Apache Ranger 0 <= 2.8.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
.