Improper access control in Cassandra - CVE-2026-27314
Published: April 7, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in ADD IDENTITY authorization handling when associating a certificate identity with an arbitrary role in an mTLS environment using MutualTlsAuthenticator. A remote user can associate their own certificate identity with an arbitrary role to escalate privileges.
Exploitation requires an mTLS environment using MutualTlsAuthenticator and CREATE permission.
Affected software
IBM Global High Availability Mailbox
How to mitigate CVE-2026-27314
IBM Global High Availability Mailbox - addressed in versions 6.2.0.6 6212, 6.2.0.6 6221