{"id":"CVE-2025-26511","aliases":["GHSA-mrqp-q7vx-v2cx"],"url":"https://o3.security/vulnerability/CVE-2025-26511","summary":"Cassandra-Lucene-Index allows bypass of Cassandra RBAC","details":"**Summary / Details**\nSystems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.0-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which when successfully exploited could allow authenticated Cassandra users to remotely bypass RBAC to access data and and escalate their privileges. \n\n**Affected Versions**\n-\tCassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 \n-\tversions 4.1.0-1.0.0 through 4.1.8-1.0.0\nwhen installed into Apache Cassandra version 4.x.\n\n**Required Configuration for Exploit**\nThese are the conditions required to enable exploit:\n1. Cassandra 4.x\n2. Vulnerable version of the Cassandra-Lucene-Index plugin configured for use\n3. Data added to tables\n4. Lucene index created\n5. Cassandra flush has run\n\n**Mitigation/Prevention**\nMitigation requires dropping all Lucene indexes and stopping use of the plugin. Exploit will be possible any time the required conditions are met.\n\n**Solution**\nUpgrade to a fixed version of the Cassandra-Lucene-Index plugin.  \nReview users in Cassandra to validate all superuser privileges.","published":"2025-02-13T15:44:06.315Z","modified":"2026-08-12T15:16:20.947994Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.instaclustr:cassandra-lucene-index-plugin","fixedVersion":"4.0.17-1.0.0"},{"ecosystem":"Maven","name":"com.instaclustr:cassandra-lucene-index-plugin","fixedVersion":"4.1.8-1.0.1"}],"fix":{"url":"https://github.com/instaclustr/cassandra-lucene-index/commit/44ab4b639c9354a6335f40b1cf6178c745c6e101","label":"instaclustr/cassandra-lucene-index@44ab4b6"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/26xxx/CVE-2025-26511.json"},{"type":"ADVISORY","url":"https://github.com/instaclustr/cassandra-lucene-index/security/advisories/GHSA-mrqp-q7vx-v2cx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-26511"},{"type":"FIX","url":"https://github.com/instaclustr/cassandra-lucene-index/commit/44ab4b639c9354a6335f40b1cf6178c745c6e101"},{"type":"PACKAGE","url":"https://github.com/instaclustr/cassandra-lucene-index"},{"type":"WEB","url":"https://github.com/instaclustr/cassandra-lucene-index/commit/94380b165bd3e597d3e22e47f8cc674ec7c7bf7f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:16:20.947994Z"}}