CVE-2026-27314Disclosure(apache / cassandra)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY. Users are recommended to upgrade to version 5.0.7+, which fixes this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-267

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cassandra

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
cassandra

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-07: 3Technical Details · 2026-04-07: 204-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets5 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Cassandra CVE-2026-27314: Privilege escalation via ADD IDENTITY authorization bypass https://www.openwall.com/lists/oss-security/2026/04/07/7 CVE-2026-27315: cqlsh history sensitive info leak https://www.openwall.com/lists/oss-security/2026/04/07/8 CVE-2026-32588: Authenticated DoS via ALTER ROLE Password Hashing https://www.openwall.com/lists/oss-security/2026/04/07/9

    Post summary

    The note lists three Apache Cassandra CVEs with brief technical descriptions and links to OpenWall discussions, but provides no PoC, exploit code, patches, or evidence of active exploitation.

    01072698
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27314 Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own cert… https://www.cve.org/CVERecord?id=CVE-2026-27314

    Post summary

    The text announces CVE-2026-27314, a privilege escalation bug in Apache Cassandra 5.0 that allows a user with only CREATE rights to bind their own certificate in an mTLS environment.

    00000137
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-27314 CVE-2026-27314 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27314

    Post summary

    The post merely lists CVE-2026-27314 twice and provides a URL to vulmon, without additional technical, exploit, or patch information.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecassandra---

Explore more