{"id":"CVE-2025-26511","summary":"Cassandra-Lucene-Index allows bypass of Cassandra RBAC","details":"Systems running the Instaclustr \nfork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 \nthrough 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into\n Apache Cassandra version 4.x, are susceptible to a vulnerability which \nwhen successfully exploited could allow authenticated Cassandra users to\n remotely bypass RBAC and escalate their privileges.","aliases":["GHSA-mrqp-q7vx-v2cx"],"modified":"2026-08-12T15:16:20.947994Z","published":"2025-02-13T15:44:06.315Z","database_specific":{"cna_assigner":"netapp","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/26xxx/CVE-2025-26511.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/26xxx/CVE-2025-26511.json"},{"type":"ADVISORY","url":"https://github.com/instaclustr/cassandra-lucene-index/security/advisories/GHSA-mrqp-q7vx-v2cx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-26511"},{"type":"FIX","url":"https://github.com/instaclustr/cassandra-lucene-index/commit/44ab4b639c9354a6335f40b1cf6178c745c6e101"},{"type":"PACKAGE","url":"https://github.com/instaclustr/cassandra-lucene-index"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/instaclustr/cassandra-lucene-index","events":[{"introduced":"ec1fcf717d35d937d3a18220f4549207deaa39fa"},{"fixed":"fa33e82ae6394aac465fafdaa69d454cbdd8ae6c"},{"introduced":"09ecb458fc605fd786ca2591b7cff7440296dd80"},{"fixed":"b9e9244bb1ef37cd1bce59ae9b66253a7ce01b10"},{"fixed":"44ab4b639c9354a6335f40b1cf6178c745c6e101"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"4.0-rc1-1.0.0"},{"fixed":"4.0.16-1.0.0"},{"introduced":"4.1.2-1.0.0"},{"fixed":"4.1.8-1.0.0"}]}}],"versions":["cassandra-4.0.16-1.0.0","cassandra-4.1.3-1.0.1","cassandra-4.1.4-1.0.0","cassandra-4.0.12-1.0.0","cassandra-4.0.11-1.0.0","cassandra-4.1.3-1.0.0","cassandra-4.1.2-1.0.0","cassandra-4.0.10-1.0.0","cassandra-4.0.9-1.0.0","cassandra-4.0.8-1.0.0","cassandra-4.0.4-1.0.0","cassandra-4.0.1-1.0.0","cassandra-4.0.0-1.0.0","cassandra-4.0-rc2-1.0.0","cassandra-4.0-rc1-1.0.1","cassandra-4.0-rc1-1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-26511.json","vanir_signatures_modified":"2026-08-12T15:16:20Z","vanir_signatures":[{"source":"https://github.com/instaclustr/cassandra-lucene-index/commit/fa33e82ae6394aac465fafdaa69d454cbdd8ae6c","target":{"file":"testsAT/src/test/java/com/stratio/cassandra/lucene/PluginTestFramework.java"},"deprecated":false,"digest":{"line_hashes":["186939951878563186827467776834455250588","138393735873116325279779801292615498542","295182913979005692175182155459810110193","253582780017469836656234364052547197546","174783625868708207901582171133453745503"],"threshold":0.9},"id":"CVE-2025-26511-d3846c74","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}