Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-32227: Apache Ranger: SQL Injection in Lookup Functionality

CVE-2026-32227 · published 1 month ago
Summary

Apache Ranger's lookup feature can be exploited to inject malicious SQL code. This can lead to unauthorized data access or modification. To fix this issue, upgrade to version 2.9.0.

What to do
  • Update apache ranger to version 2.9.0 or later.
Affected software
VendorProductAffected versions
apache software foundation apache ranger All versions
apache ranger < 2.9.0
cpe:2.3:a:apache:ranger:*:*:*:*:*:*:*:*
Original advisory text
SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue.
SQL Injection vulnerability vulnerability in Apache Ranger.

This issue affects .

Users are recommended to upgrade to version 2.9.0, which fixes the issue.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published10 Aug 2026
Updated25 Sep 2026
First seen10 Aug 2026
Sources
CVE-2026-32227 · MITRE
Track software like this
Free during beta