Количество 3
Количество 3
CVE-2026-27314
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY. Users are recommended to upgrade to version 5.0.7+, which fixes this issue.
CVE-2026-27314
Privilege escalationin Apache Cassandra 5.0 on an mTLS environment usi ...
GHSA-qxpc-96fq-wwmg
Apache Cassandra is vulnerable to privilege escalation in an mTLS environment using MutualTlsAuthenticator
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-27314 Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY. Users are recommended to upgrade to version 5.0.7+, which fixes this issue. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-27314 Privilege escalationin Apache Cassandra 5.0 on an mTLS environment usi ... | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
GHSA-qxpc-96fq-wwmg Apache Cassandra is vulnerable to privilege escalation in an mTLS environment using MutualTlsAuthenticator | CVSS3: 8.8 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу