CVE-2026-28672
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.
- Affected products
- Apache Ranger
- Apache Ranger
- ≤ 2.8.0
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.3% (68th percentile)
- Weakness
- CWE-77
- NVD status
- Analyzed
- Published
- 2026-08-10
CVE-2026-28672 at NVD
2 known exploits for CVE-2026-28672
Proof-of-concept code and exploit modules indexed by Sploitus