Privilege Escalation Vulnerability in Apache Cassandra by The Apache Software Foundation
CVE-2025-26467
8.8HIGH
What is CVE-2025-26467?
A privilege escalation vulnerability exists in Apache Cassandra where a user granted MODIFY permissions on all keyspaces can execute unsafe actions, allowing them to elevate their privileges to superuser status within a targeted Cassandra cluster. Operators who have assigned data MODIFY permissions should verify and review their data access controls to prevent potential exploitation. Particularly, users running version 4.0.16 are advised to upgrade to version 4.0.17 for resolution, while users on versions 3.0, 3.11, 4.1, and 5.0 should follow the recommendations outlined in associated advisories.
Affected Version(s)
Apache Cassandra 4.0.16
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adam Pond of Apple Services Engineering Security
Ali Mirheidari of Apple Services Engineering Security
Terry Thibault of Apple Services Engineering Security
Will Brattain of Apple Services Engineering Security