#VU118677 Incorrect authorization in Cassandra - CVE-2025-24860
Published: November 21, 2025
Cassandra
Apache Foundation
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability in Apache Cassandra allows users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer.. A remote user with restricted data center access can update their own permissions via data control language (DCL) statements on affected versions.