Critical severity9.8NVD Advisory· Published Aug 10, 2026· Updated Aug 17, 2026
CVE-2026-28672
CVE-2026-28672
Description
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger.
This issue affects Apache Ranger: from 0.6 through 2.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.ranger:rangerMaven | >= 0.6.0, <= 2.8.0 | — |
Affected products
2Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2026/08/09/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-6qc3-v8fv-fv9jghsaADVISORY
- lists.apache.org/thread/99ysjqcmz950o3jgm6pqx1wb696onzq7nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-28672ghsaADVISORY
News mentions
0No linked articles in our index yet.