{"id":"GHSA-mrqp-q7vx-v2cx","summary":"Instaclustr Cassandra-Lucene-Index allows bypass of Cassandra RBAC","details":"**Summary / Details**\nSystems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.0-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which when successfully exploited could allow authenticated Cassandra users to remotely bypass RBAC to access data and and escalate their privileges. \n\n**Affected Versions**\n-\tCassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 \n-\tversions 4.1.0-1.0.0 through 4.1.8-1.0.0\nwhen installed into Apache Cassandra version 4.x.\n\n**Required Configuration for Exploit**\nThese are the conditions required to enable exploit:\n1. Cassandra 4.x\n2. Vulnerable version of the Cassandra-Lucene-Index plugin configured for use\n3. Data added to tables\n4. Lucene index created\n5. Cassandra flush has run\n\n**Mitigation/Prevention**\nMitigation requires dropping all Lucene indexes and stopping use of the plugin. Exploit will be possible any time the required conditions are met.\n\n**Solution**\nUpgrade to a fixed version of the Cassandra-Lucene-Index plugin.  \nReview users in Cassandra to validate all superuser privileges.","aliases":["CVE-2025-26511"],"modified":"2026-02-03T03:09:14.054754Z","published":"2025-02-13T17:16:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-02-13T17:16:27Z","nvd_published_at":"2025-02-13T16:16:50Z","cwe_ids":["CWE-288","CWE-863"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/instaclustr/cassandra-lucene-index/security/advisories/GHSA-mrqp-q7vx-v2cx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-26511"},{"type":"WEB","url":"https://github.com/instaclustr/cassandra-lucene-index/commit/44ab4b639c9354a6335f40b1cf6178c745c6e101"},{"type":"WEB","url":"https://github.com/instaclustr/cassandra-lucene-index/commit/94380b165bd3e597d3e22e47f8cc674ec7c7bf7f"},{"type":"PACKAGE","url":"https://github.com/instaclustr/cassandra-lucene-index"}],"affected":[{"package":{"name":"com.instaclustr:cassandra-lucene-index-plugin","ecosystem":"Maven","purl":"pkg:maven/com.instaclustr/cassandra-lucene-index-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0-rc1-1.0.0"},{"fixed":"4.0.17-1.0.0"}]}],"versions":["4.0.0-1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-mrqp-q7vx-v2cx/GHSA-mrqp-q7vx-v2cx.json"}},{"package":{"name":"com.instaclustr:cassandra-lucene-index-plugin","ecosystem":"Maven","purl":"pkg:maven/com.instaclustr/cassandra-lucene-index-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0-1.0.0"},{"fixed":"4.1.8-1.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-mrqp-q7vx-v2cx/GHSA-mrqp-q7vx-v2cx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}