Severity: moderate Affected versions:
- Apache Ranger (org.apache.ranger.unixusersync) 0.6 through 2.8
Description:
Improper Neutralization of Special Elements used in a Command ('Command
Injection') vulnerability in Apache Ranger.
This issue affects Apache Ranger: from 0.6 through 2.8.
Credit:
Andrea Cosentino (finder)
References:
https://ranger.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-28672
