CVE-2025-59059

Published Mar 3, 2026

Last updated 2 months ago

Overview

Description
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.
Source
security@apache.org
NVD status
Analyzed
Products
ranger

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@apache.org
CWE-94

Social media

Hype score
Not currently trending
  1. CVE-2025-59060: Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient https://t.co/hCdHrz5KcI CVE-2025-59059: Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator https://t.co/VU24BoIYUe Both are "Severity: low"

    @oss_security

    8 Mar 2026

    584 Impressions

    0 Retweets

    5 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  2. 🔴 CVE-2025-59059 - Critical Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &amp;lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this is... https://t.co/rFIo7eHsRB https://t.co/I4QyDThGOr

    @TheHackerWire

    3 Mar 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔴 CVE-2025-59059 - Critical Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &amp;lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this is... https://t.co/rFIo7eHsRB https://t.co/rBTAygaU2L

    @TheHackerWire

    3 Mar 2026

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔴 CVE-2025-59059 - Critical Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &amp;lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this is... https://t.co/rFIo7eHsRB https://t.co/wWOezypHQG

    @TheHackerWire

    3 Mar 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨*CVE* CVE-2025-59059 Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, w… https://t.co/1oZViDdeTf ----- Traducción: CVE-2025-59059 Vul… https://t.co/utm

    @infoflowcloud

    3 Mar 2026

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-59059 Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions &lt;= 2.7.0. Users are recommended to upgrade to version 2.8.0, w… https://t.co/GuOzCWdCmT

    @CVEnew

    3 Mar 2026

    435 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-59059 CVE-2025-59059 https://t.co/gqdGrPA1dG

    @VulmonFeeds

    3 Mar 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations