CVE-2025-26511

Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which when successfully exploited could allow authenticated Cassandra users to remotely bypass RBAC and escalate their privileges.
Configurations

No configuration.

History

22 Jan 2026, 20:16

Type Values Removed Values Added
References
  • () https://github.com/instaclustr/cassandra-lucene-index/commit/44ab4b639c9354a6335f40b1cf6178c745c6e101 -
Summary
  • (es) Los sistemas que ejecutan la bifurcación Instaclustr del complemento Cassandra-Lucene-Index de Stratio, versiones 4.0-rc1-1.0.0 a 4.0.16-1.0.0 y 4.1.2-1.0.0 a 4.1.8-1.0.0, instaladas en Apache Cassandra versión 4.x, son susceptibles a una vulnerabilidad que, cuando se explota con éxito, podría permitir a los usuarios autenticados de Cassandra eludir de forma remota el RBAC y aumentar sus privilegios.

14 Feb 2025, 00:15

Type Values Removed Values Added
CWE CWE-288 CWE-863

13 Feb 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-13 16:16

Updated : 2026-01-22 20:16


NVD link : CVE-2025-26511

Mitre link : CVE-2025-26511

CVE.ORG link : CVE-2025-26511


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization