What is CVE-2026-65945?
CVE-2026-65945 is a vulnerability in Apache Ranger versions <= 2.8.0 where logs contain replayable JWT tokens, potentially allowing attackers to reuse captured tokens for unauthorized access. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Azərbaycanca: CVE-2026-65945, Apache Ranger-in 2.8.0 və daha əvvəlki versiyalarında log fayllarında təkrar istifadə edilə bilən JWT tokenlərin aşkarlanması ilə bağlı zəiflikdir. Bu, təcavüzkarlara tokenləri ələ keçirərək icazəsiz giriş əldə etməyə imkan verir. İstifadəçilərə bu problemi həll edən 2.9.0 versiyasına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-522
FAQ2
Which versions of Apache Ranger are affected by CVE-2026-65945?
Versions 2.8.0 and earlier.
How can I fix CVE-2026-65945?
Upgrade to Apache Ranger version 2.9.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.