What is CVE-2026-28672?
This CVE describes a critical Command Injection vulnerability in Apache Ranger. Affecting versions from 0.6 to 2.8, it allows an unauthenticated remote attacker to execute arbitrary commands on the affected system by manipulating special elements. Apache Ranger users must immediately upgrade to a patched version.
Azərbaycanca: Bu CVE, Apache Ranger-da aşkarlanmış ciddi Command Injection zəifliyidir. 0.6-dan 2.8-ə qədər versiyaları təsir edir, autentifikasiya olunmamış uzaqdan hücumçuya təsirlənmiş sistemdə xüsusi simvollar vasitəsilə ixtiyari əmrlər icra etməyə imkan verir. Apache Ranger istifadəçiləri dərhal yamaqlanmış versiyaya keçməlidir.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: Apache
FAQ2
What threat does CVE-2026-28672 pose in Apache Ranger?
It is a critical Command Injection vulnerability that allows an unauthenticated remote attacker to execute arbitrary commands on the affected system by manipulating special elements.
Which Apache Ranger versions are affected by this vulnerability?
The vulnerability affects Apache Ranger versions from 0.6 to 2.8. Users must immediately upgrade to a patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.