CVE-2025-59059: Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator
Published Mar 2, 2026
·Updated
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.
Affected Software
2 affected components
Apache Ranger<=2.7.0
Apache Ranger<2.8.0
Event History
Mar 3, 2026
CVE Published
via MITRE·10:44 AM
Data Sourced
via MITRE·10:44 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59059?
CVE-2025-59059 is a high-severity remote code execution vulnerability in Apache Ranger.
2
How do I fix CVE-2025-59059?
To fix CVE-2025-59059, users should upgrade Apache Ranger to version 2.8.0 or later.
3
Which versions of Apache Ranger are affected by CVE-2025-59059?
Apache Ranger versions 2.7.0 and earlier are affected by CVE-2025-59059.
4
What can happen if CVE-2025-59059 is exploited?
If exploited, CVE-2025-59059 allows an attacker to execute arbitrary code on the server running Apache Ranger.
5
Is there a workaround for CVE-2025-59059?
There are no documented workarounds for CVE-2025-59059; the only resolution is to upgrade to version 2.8.0.