Vulnerabilities
Vulnerable Software
Apache:  >> Cassandra  >> 5.0.6  Security Vulnerabilities
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
CVSS Score
6.5
EPSS Score
0.001
Published
2026-04-07
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY. Users are recommended to upgrade to version 5.0.7+, which fixes this issue.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-04-07


Contact Us

Shodan ® - All rights reserved