PT-2026-30915 · Apache · Apache Cassandra+1

Ekaterina Dimitrova

+1

·

Published

2026-04-07

·

Updated

2026-05-18

·

CVE-2026-27315

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Cassandra versions 4.0 through 4.0.19
Description Apache Cassandra's command-line tool, cqlsh, saves command history in the ~/.cassandra/cqlsh history file. This file does not redact sensitive information, meaning passwords used in cqlsh commands are stored in cleartext on disk.
Recommendations Upgrade to version 4.0.20 or later.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CASSANDRA-2026-27315
CLEANSTART-2026-DD05788
CLEANSTART-2026-RN56220
CVE-2026-27315
GHSA-FH34-C629-P8XJ

Affected Products

Apache Cassandra
Cqlsh