PT-2026-22728 · Apache · Apache Ranger

Chengtianyi

·

Published

2026-03-03

·

Updated

2026-03-08

·

CVE-2025-59059

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Ranger versions prior to 2.8.0
Description A Remote Code Execution issue exists in the NashornScriptEngineCreator component of Apache Ranger. An unauthenticated remote attacker may be able to execute code on the system.
Recommendations Upgrade to version 2.8.0 or later to resolve this issue.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-59059
GHSA-C87W-642H-M97H

Affected Products

Apache Ranger