PT-2026-30903 · Apache · Apache Cassandra

·

CVE-2026-27314

·

Published

2026-04-07

·

Updated

2026-06-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Cassandra versions 5.0 through 5.0.6
Description A privilege escalation issue exists in Apache Cassandra 5.0 when using MutualTlsAuthenticator in an mTLS environment. A user with only CREATE permission can associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via the ADD IDENTITY function.
Recommendations Upgrade to version 5.0.7 or later.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27314
GHSA-QXPC-96FQ-WWMG

Affected Products

Apache Cassandra