CVE-2026-28672

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
10/08/2026
Last modified:
17/08/2026

Description

Improper Neutralization of Special Elements used in a Command (&amp;#39;Command Injection&amp;#39;) vulnerability in Apache Ranger.<br /> <br /> This issue affects Apache Ranger: from 0.6 through 2.8.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:* 0.6.0 (including) 2.8.0 (including)