CVE-2026-40920
published 2026-08-10CVE-2026-40920: Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this…
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.51%
41.3th percentile
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_ranger | <= 2.8.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
ghsa_unreviewed·2026-08-10
CVE-2026-40920 CWE-20 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
VulDB
Apache Ranger URL Parameter privileges management
vuldb·2026-08-09
CVE-2026-40920 [CRITICAL] Apache Ranger URL Parameter privileges management
A vulnerability marked as critical has been reported in Apache Ranger. Affected is an unknown function of the component URL Parameter. This manipulation causes improper privilege management.
This vulnerability is registered as CVE-2026-40920. Remote exploitation of the attack is possible. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-10
Published