What is CVE-2026-65948?
CVE-2026-65948 relates to the lack of brute-force protection in the UnixAuth component of Apache Ranger versions up to 2.8.0. UnixAuth is not recommended for production deployments. Users should upgrade to version 2.9.0 to fix this issue.
Azərbaycanca: CVE-2026-65948 Apache Ranger-in 2.8.0 və daha əvvəlki versiyalarında UnixAuth komponentində brute-force müdafiəsinin olmaması ilə bağlıdır. UnixAuth istehsal mühitləri üçün tövsiyə edilmir. Bu problemi həll etmək üçün 2.9.0 versiyasına yüksəltmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Apache
FAQ2
Which Apache Ranger component is affected by CVE-2026-65948?
CVE-2026-65948 relates to the lack of brute-force protection in the UnixAuth component of Apache Ranger.
To which version should users upgrade to fix CVE-2026-65948?
Users should upgrade to Apache Ranger version 2.9.0 to fix this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.