CVE-2026-40920 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-40920 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-40920 is a critical privilege-escalation vulnerability in Apache Ranger versions 2.8.0 and earlier that is associated with URL parameter handling.
Technical Detail
The reported flaw allows privilege escalation through manipulation of a URL parameter in affected Apache Ranger deployments. An authenticated or otherwise suitably positioned attacker may be able to abuse the vulnerable request handling to obtain permissions beyond those assigned to their account. The available advisory information does not specify the affected endpoint, required privileges, or the exact authorization-control bypass mechanism.
Exploitation Status
No known public exploit or confirmed in-the-wild exploitation has been reported as of August 17, 2026. CVE-2026-40920 is not listed in CISA's Known Exploited Vulnerabilities catalog.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Upgrade Apache Ranger to version 2.9.0, which fixes this issue, with priority given to internet-accessible management interfaces and environments where Ranger controls access to sensitive data platforms. Until upgrades are complete, restrict access to Ranger administrative and user interfaces to trusted networks and authorized users, enforce least-privilege role assignments, and review Ranger audit and web access logs for unusual URL parameter values, unexpected authorization changes, or administrative activity performed by lower-privileged accounts. No vendor-documented workaround or detection signature has been provided.