Incorrect authorization in Cassandra - CVE-2025-24860

 

Incorrect authorization in Cassandra - CVE-2025-24860

Published: November 21, 2025


Vulnerability identifier: #VU118677
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24860
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability in Apache Cassandra allows users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer.. A remote user with restricted data center access can update their own permissions via data control language (DCL) statements on affected versions.


Affected software

Cassandra
Netcool Operations Insight

How to mitigate CVE-2025-24860

Install updates from vendor's website.

Cassandra - addressed in versions 4.0.16, 4.1.8, 5.0.3
Netcool Operations Insight - update to 1.6.15

External References

Related Security Bulletins