CVE-2026-55814
published 2026-08-10CVE-2026-55814: Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.48%
39.5th percentile
Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_ranger | <= 2.8.0 | — |
| rhacm2 | volsync-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache Ranger: Apache Ranger: Information disclosure via missing authentication in download APIs
vendor_redhat·2026-08-10·CVSS 7.5
CVE-2026-55814 [HIGH] CWE-306 Apache Ranger: Apache Ranger: Information disclosure via missing authentication in download APIs
Apache Ranger: Apache Ranger: Information disclosure via missing authentication in download APIs
A flaw was found in Apache Ranger. This vulnerability allows a remote attacker to access sensitive plugin data through the download APIs without requiring any authentication. This unauthorized access can lead to information disclosure, potentially exposing critical configuration or operational details.
Package: rhacm2/volsync-rhel9 (Red Hat Advanced Cluster Management for Kubernetes 2) - Fix deferred
GHSA
Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0.
ghsa_unreviewed·2026-08-10
CVE-2026-55814 [HIGH] CWE-306 Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0.
Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
VulDB
Apache Ranger missing authentication
vuldb·2026-08-09
CVE-2026-55814 [LOW] Apache Ranger missing authentication
A vulnerability classified as problematic was found in Apache Ranger. This affects an unknown part. Executing a manipulation can lead to missing authentication.
This vulnerability appears as CVE-2026-55814. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
2026-08-10
Published