CVE-2026-44416: Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Ranger (plugin-schema-registry)to a version that resolves this vulnerability.Fixed in 2.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44416?
CVE-2026-44416 has a risk rating of 82, indicating a high severity level.
How do I fix CVE-2026-44416?
To fix CVE-2026-44416, upgrade Apache Ranger to version 2.9.0 or later.
What type of vulnerability is CVE-2026-44416?
CVE-2026-44416 is classified as a Code Injection vulnerability that allows remote code execution.
Which component in Apache Ranger is affected by CVE-2026-44416?
CVE-2026-44416 affects the plugin-schema-registry component in Apache Ranger.
Which versions of Apache Ranger are vulnerable to CVE-2026-44416?
Apache Ranger versions up to and including 2.8.0 are vulnerable to CVE-2026-44416.