Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role,
including a superuser role, and authenticate as that role via ADD IDENTITY.
Users are recommended to upgrade to version 5.0.7+, which fixes this issue.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY. Users are recommended to upgrade to version 5.0.7+, which fixes this issue. | |
| Title | Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass | |
| Weaknesses | CWE-267 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-07T17:48:03.999Z
Reserved: 2026-02-19T00:03:57.862Z
Link: CVE-2026-27314
Updated: 2026-04-07T17:25:57.687Z
Status : Received
Published: 2026-04-07T17:16:27.693
Modified: 2026-04-07T18:16:40.567
Link: CVE-2026-27314
No data.
OpenCVE Enrichment
No data.