
🚨Critical - Apache Ranger Schema Registry Plugin RCE via Arbitrary Class Instantiation (CVE-2026-44416) Apache Ranger plugin-schema-registry allows externally controlled input to influence reflective class selection/instantiation, enabling unsafe reflection/code injection to load attacker-chosen classes and achieve remote code execution. Deployments not using the plugin-schema-registry component are not impacted. 👉Affected: Apache Ranger plugin-schema-registry <= 2.8.0 | Upgrade to 2.9.0
Post summary
Apache Ranger plugin-schema-registry versions 2.8.0 and earlier are vulnerable to remote code execution via arbitrary class instantiation; the vulnerability is mitigated by upgrading to version 2.9.0.
