CVE-2026-65948: Apache Ranger: UnixAuth lacks brute-force protection
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option for production deployments. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Rangerto a version that resolves this vulnerability.Fixed in 2.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65948?
CVE-2026-65948 has a risk rating of 33.
How do I fix CVE-2026-65948?
To fix CVE-2026-65948, upgrade Apache Ranger to version 2.9.0 or higher.
What does CVE-2026-65948 affect?
CVE-2026-65948 affects the UnixAuth authentication method in Apache Ranger versions 2.8.0 and lower.
What is the main issue with CVE-2026-65948?
The main issue with CVE-2026-65948 is that UnixAuth lacks brute-force protection.
Is UnixAuth recommended for production environments given CVE-2026-65948?
No, UnixAuth is not recommended for production deployments due to its security vulnerabilities such as CVE-2026-65948.