Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-32227: Apache Ranger: SQL Injection in Lookup Functionality
CVE-2026-32227 · published 1 month ago
Summary
Apache Ranger's lookup feature can be exploited to inject malicious SQL code. This can lead to unauthorized data access or modification. To fix this issue, upgrade to version 2.9.0.
What to do
- Update apache ranger to version 2.9.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache ranger | All versions |
| apache | ranger |
< 2.9.0 cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:* |
Original advisory text
SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recommended to upgrade to version 2.9.0, which fixes the issue.
SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recommended to upgrade to version 2.9.0, which fixes the issue.
This issue affects .
Users are recommended to upgrade to version 2.9.0, which fixes the issue.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published10 Aug 2026
Updated25 Sep 2026
First seen10 Aug 2026
Track software like this
Free during beta