CVE-2026-32227 PUBLISHED

Apache Ranger: SQL Injection vulnerability in lookup functionality

Assigner: apache
Reserved: 11.03.2026 Published: 10.08.2026 Updated: 10.08.2026

SQL Injection vulnerability vulnerability in Apache Ranger.

This issue affects .

Users are recommended to upgrade to version 2.9.0, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Ranger
Versions Default: unaffected
  • unknown from 2.0.0 to 2.8.0 (incl.)

Credits

  • 罗鑫 <lx2317103712@gmail.com> finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE