CVE-2026-65948
Received Received - Intake

UnixAuth Brute-Force Protection Flaw in Apache Ranger

Vulnerability report for CVE-2026-65948, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Apache Software Foundation

Description

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, which fixes this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache ranger to 2.8.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

UnixAuth in Apache Ranger versions 2.8.0 or earlier lacks brute-force protection, allowing repeated login attempts without detection or lockout. This makes it easier for attackers to guess credentials through brute-force attacks.

Detection Guidance

This vulnerability can be detected by checking the Apache Ranger version installed on your system. If it is version 2.8.0 or lower, the system is vulnerable. Run the command: 'ranger-admin version' or check the version in the Ranger admin UI. Additionally, review authentication logs for repeated failed login attempts targeting UnixAuth, as the lack of brute-force protection may allow multiple attempts.

Impact Analysis

Attackers could gain unauthorized access to systems using Apache Ranger by exploiting weak authentication in UnixAuth, potentially leading to data breaches or unauthorized actions.

Compliance Impact

This vulnerability may violate compliance requirements for access controls and authentication, such as those in GDPR or HIPAA, by failing to implement adequate brute-force protection.

Mitigation Strategies

Upgrade Apache Ranger to version 2.9.0 or later to address the UnixAuth brute-force protection issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65948. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart