CVE-2026-40920 PUBLISHED

Apache Ranger: Privilege Escalation via URL Parameter

Assigner: apache
Reserved: 15.04.2026 Published: 10.08.2026 Updated: 10.08.2026

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.

Users are recommended to upgrade to version 2.9.0, which fixes this issue.

Product Status

Vendor Apache Software Foundation
Product Apache Ranger
Versions Default: unaffected
  • affected from 0 to 2.8.0 (incl.)

Credits

  • Andrew Rukin (Arenadata) finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE
  • CWE-20 Improper Input Validation CWE
  • CWE-287 Improper Authentication CWE