CVE-2025-59059
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.
- Affected products
- Apache Ranger
- Apache Ranger
- < 2.8.0
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.2% (67th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2026-03-03
CVE-2025-59059 at NVD
2 known exploits for CVE-2025-59059
Proof-of-concept code and exploit modules indexed by Sploitus