Apache Ranger RCEs and FIPS 207 key format
Multiple remote code execution flaws and other vulnerabilities were disclosed in Apache Ranger versions up to 2.8.0, alongside a critical issue in Apache Tapestry. The NIST PQC forum also examined a proposed seed-only key format for HQC-KEM in the forthcoming FIPS 207 draft.
Apache Ranger remote code execution via JDBC URL injection
Apache Ranger versions up to 2.8.0 contain a remote code execution vulnerability identified as CVE-2026-42537 that stems from JDBC URL injection. The project recommends upgrading to remediate the flaw. Deployments of Ranger should treat this as a high-priority patch given the potential for unauthenticated code execution.
NIST seed-only key format proposal for HQC-KEM in FIPS 207
The NIST PQC forum discussed an upcoming FIPS 207 draft that proposes a seed-only key format for HQC-KEM. This differs from the dual formats supported by ML-KEM and draws on interoperability feedback. Implementers of post-quantum cryptography need to track the divergence for future compliance.
Apache Ranger remote code execution via arbitrary class instantiation
Apache Ranger disclosed CVE-2026-44416, a remote code execution issue caused by arbitrary class instantiation in the plugin-schema-registry component. Versions up to 2.8.0 are affected. The vulnerability expands the set of critical flaws requiring immediate upgrades in Ranger environments.
Apache Ranger OS command injection in UnixUserGroupBuilder
CVE-2026-28672 covers a moderate-severity OS command injection vulnerability in Apache Ranger's UnixUserGroupBuilder that affects versions from 0.6 through 2.8. The flaw is triggered via username handling. Administrators running these releases should apply updates to prevent command injection attacks.
Apache Tapestry classpath file download via URL manipulation
Apache Tapestry versions 5.5 through 5.9.0 contain a critical vulnerability, CVE-2026-61899, that allows classpath asset downloads through crafted URLs. The issue is fixed in version 5.9.1. Applications built on the affected Tapestry releases risk exposure of internal resources and should upgrade promptly.
Apache Ranger privilege escalation via URL parameter
CVE-2026-40920 describes a privilege escalation flaw in Apache Ranger versions up to 2.8.0 that is reachable through a URL parameter. The issue permits elevation of privileges under certain conditions. Operators should include this fix in their upgrade plans for Ranger.
Apache Ranger clients accept mismatched TLS hostnames
A moderate TLS hostname verification flaw, CVE-2026-65942, affects Apache Ranger clients up to version 2.8.0. Clients accept certificates issued for other hostnames. This weakens transport security and warrants attention in environments relying on Ranger client connections.
Apache Ranger download APIs expose plugin data without authentication
CVE-2026-55814 is a low-severity authentication bypass in Apache Ranger versions up to 2.8.0 that allows download APIs to expose plugin data. The flaw requires no authentication for access. While lower impact, it still merits remediation alongside the higher-severity Ranger issues.