Improper access control in Cassandra - CVE-2026-27314

 

Improper access control in Cassandra - CVE-2026-27314

Published: April 7, 2026


Vulnerability identifier: #VU125100
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27314
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in ADD IDENTITY authorization handling when associating a certificate identity with an arbitrary role in an mTLS environment using MutualTlsAuthenticator. A remote user can associate their own certificate identity with an arbitrary role to escalate privileges.

Exploitation requires an mTLS environment using MutualTlsAuthenticator and CREATE permission.


Affected software

Cassandra
IBM Global High Availability Mailbox

How to mitigate CVE-2026-27314

Install security update from vendor's website.

Cassandra - update to 5.0.7
IBM Global High Availability Mailbox - addressed in versions 6.2.0.6 6212, 6.2.0.6 6221

External References

Related Security Bulletins