CVE-2026-65942
published 2026-08-10CVE-2026-65942: TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.56%
44.5th percentile
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ranger | < 2.9.0 | 2.9.0 |
| apache_software_foundation | apache_ranger | <= 2.8.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
ghsa_unreviewed·2026-08-10
CVE-2026-65942 [HIGH] CWE-297 TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
VulDB
Apache Ranger certificate validation
vuldb·2026-08-09
CVE-2026-65942 [LOW] Apache Ranger certificate validation
A vulnerability described as problematic has been identified in Apache Ranger. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper certificate validation.
This vulnerability is documented as CVE-2026-65942. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-10
Published