https://seclists.org/oss-sec/2026/q1/245: CVE-2025-59059: Apache Ranger: mote Code Execution Vulnerability in NashornScriptEngineCator
Published Mar 2, 2026
·Updated
Affected Software
1 affected component
Apache Ranger<=2.7.0
Frequently Asked Questions
1
What is the severity of CVE-2025-59059?
The severity of CVE-2025-59059 is classified as low.
2
What versions of Apache Ranger are affected by CVE-2025-59059?
Apache Ranger versions up to and including 2.7.0 are affected by CVE-2025-59059.
3
How do I fix CVE-2025-59059?
To fix CVE-2025-59059, users should upgrade to Apache Ranger version 2.8.0 or later.
4
What type of vulnerability is CVE-2025-59059?
CVE-2025-59059 is a remote code execution vulnerability in the NashornScriptEngineCreator component.
5
When was CVE-2025-59059 published?
CVE-2025-59059 was published on March 2, 2026.