CVE-2026-28672
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger.
This issue affects Apache Ranger: from 0.6 through 2.8.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
http://www.openwall.com/lists/oss-security/2026/08/09/2, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28672.json, https://lists.apache.org/thread/99ysjqcmz950o3jgm6pqx1wb696onzq7, https://nvd.nist.gov/vuln/detail/CVE-2026-28672