← Back to browse · API

CVE-2026-28672

Severity
CRITICAL
CVSS
9.8
EPSS
0.01975
Risk score
39.89
CISA KEV
No
PoC
No
Published
2026-08-10
Modified
2026-08-12
First seen
2026-08-10
Aliases
EUVD-2026-55254, GHSA-6QC3-V8FV-FV9J
Products
Apache Software Foundation:Apache Ranger 0.6 ≤2.8
Sources
nvd CVE-2026-28672
euvd EUVD-2026-55254

Description

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.

References