
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59059 is a Remote Code Execution (RCE) vulnerability in the NashornScriptEngineCreator component of Apache Ranger, affecting versions 2.7.0 and earlier. Disclosed on March 2, 2026 via the oss-security mailing list by Velmurugan Periasamy (Apache), the vulnerability was credited to researcher chengtianyi (OSS-Security). It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting network-accessible exploitation with no authentication or user interaction required (Feedly). Affected products also include IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data, which bundle Apache Ranger (IBM Advisory).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), specifically within the NashornScriptEngineCreator class in Apache Ranger (OSS-Security). The Nashorn JavaScript engine, embedded in the JVM, is used by Apache Ranger for script-based policy evaluation; insufficient validation of user-supplied input allows an attacker to inject and execute arbitrary JavaScript/JVM code through this engine. The attack vector is network-based, requires no privileges and no user interaction, and has low attack complexity, making it trivially exploitable against exposed instances (Feedly). A GitHub repository has appeared claiming to provide static analysis corrections regarding the misattribution of the RCE, suggesting some nuance in the exploitability assessment may be under community review (GitHub).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the host running Apache Ranger, resulting in full system compromise across all three security dimensions: confidentiality (data theft, credential exposure), integrity (system and configuration modification), and availability (service disruption or denial) (Feedly). Given Apache Ranger's role as a centralized security and policy management framework for big data ecosystems (Hadoop, Hive, HBase, Kafka, etc.), a compromised Ranger instance could allow an attacker to pivot to connected data platform components and manipulate access control policies across the entire data estate. IBM products embedding Apache Ranger are also at risk, broadening the affected asset scope (IBM Advisory).
NashornScriptEngineCreator for script-based policy evaluation. This is typically associated with Ranger's policy condition or custom condition scripting features.java.lang.Runtime.exec() or ProcessBuilder from within the JavaScript context).NashornScriptEngineCreator or ScriptEngine evaluation errors in Ranger application logs./bin/sh, bash, cmd.exe, curl, wget, python); unexpected network connections initiated by the Java process.The primary remediation is to upgrade Apache Ranger to version 2.8.0 or later, which resolves this vulnerability (OSS-Security). IBM has also released a security bulletin for affected Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data products, and users of those platforms should apply the relevant IBM patches (IBM Advisory). For organizations unable to patch immediately, recommended interim mitigations include: restricting network access to Apache Ranger admin interfaces via firewall rules or network segmentation, deploying network-based IDS/IPS to monitor for exploitation attempts, and reviewing Ranger access logs for anomalous activity targeting script evaluation endpoints.
The vulnerability was disclosed via the Apache oss-security mailing list and the Apache Ranger announce list, with the original reporter noting a severity of "low" — in contrast to the NVD-assigned CVSS score of 9.8 (Critical), which has generated some community discussion (OSS-Security). A GitHub repository was created specifically to challenge the RCE classification, suggesting the security research community is actively debating the true exploitability and impact of this vulnerability (GitHub). Security news outlets including The Hacker Wire and Infinit Security covered the disclosure, and the vulnerability was noted in Qualys application security detection updates for March 2026 (Qualys).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."