Cleartext storage of sensitive information in Cassandra - CVE-2026-27315
Published: April 7, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper handling of sensitive information in the cqlsh history file when saving previously executed cqlsh commands. A local user can read the local ~/.cassandra/cqlsh_history file to disclose sensitive information.
Passwords used in commands such as login or user creation may be stored in cleartext in the history file.
Affected software
Datastax Enterprise with IBM
How to mitigate CVE-2026-27315
Datastax Enterprise with IBM - update to 6.9.24