top of page
perceptive_background_267k.jpg

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0.
Users are recommended to upgrade to version 2.…

Published:

2 maart 2026 om 23:00:00

Alert date:

3 maart 2026 om 16:02:37

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Security Tools

A remote code execution vulnerability has been identified in the NashornScriptEngineCreator component of Apache Ranger versions 2.7.0 and earlier. This vulnerability allows attackers to execute arbitrary code remotely on affected systems. The issue affects all Apache Ranger installations running versions up to and including 2.7.0. Users are strongly recommended to upgrade to version 2.8.0, which contains a fix for this security flaw. The vulnerability has been assigned CVE-2025-59059 and is considered high severity due to the potential for complete system compromise through remote code execution.

Technical details

Mitigation steps:

Affected products:

Apache Ranger

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page