{"id":"CVE-2025-26511","aliases":["GHSA-mrqp-q7vx-v2cx"],"url":"https://o3.security/vulnerability/CVE-2025-26511","summary":"Cassandra-Lucene-Index allows bypass of Cassandra RBAC","details":"Systems running the Instaclustr \nfork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 \nthrough 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into\n Apache Cassandra version 4.x, are susceptible to a vulnerability which \nwhen successfully exploited could allow authenticated Cassandra users to\n remotely bypass RBAC and escalate their privileges.","published":"2025-02-13T15:44:06.315Z","modified":"2026-07-22T03:36:23.273669Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.instaclustr:cassandra-lucene-index-plugin","fixedVersion":"4.0.17-1.0.0"},{"ecosystem":"Maven","name":"com.instaclustr:cassandra-lucene-index-plugin","fixedVersion":"4.1.8-1.0.1"}],"fix":{"url":"https://github.com/instaclustr/cassandra-lucene-index/commit/44ab4b639c9354a6335f40b1cf6178c745c6e101","label":"instaclustr/cassandra-lucene-index@44ab4b6"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/26xxx/CVE-2025-26511.json"},{"type":"ADVISORY","url":"https://github.com/instaclustr/cassandra-lucene-index/security/advisories/GHSA-mrqp-q7vx-v2cx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-26511"},{"type":"FIX","url":"https://github.com/instaclustr/cassandra-lucene-index/commit/44ab4b639c9354a6335f40b1cf6178c745c6e101"},{"type":"PACKAGE","url":"https://github.com/instaclustr/cassandra-lucene-index"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-22T03:36:23.273669Z"}}