CVE-2026-40920: Apache Ranger: Privilege Escalation via URL Parameter
Published Aug 10, 2026
·Updated
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Affected Software
1 affected component
Apache Ranger<=2.8.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Rangerto a version that resolves this vulnerability.Fixed in 2.9.0
Event History
Aug 10, 2026
CVE Published
via MITRE·10:25 AM
Data Sourced
via MITRE·10:25 AM
DescriptionWeakness