CVE-2025-26511
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/02/2025
Last modified:
14/02/2025
Description
Systems running the Instaclustr <br />
fork of Stratio&#39;s Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 <br />
through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into<br />
Apache Cassandra version 4.x, are susceptible to a vulnerability which <br />
when successfully exploited could allow authenticated Cassandra users to<br />
remotely bypass RBAC and escalate their privileges.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH