VendorsApachecassandraall versions
Vulnerabilities

Apache Software Foundation Cassandra

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2016-3427
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
Published 2016-04-21 · Analyzed
10.0KEVEPSS 0.923
CVE-2018-8016
The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was introduced in https://issues.apache.org/jira/browse/CASSANDRA-12109. The fix for the regression is implemented in https://issues.apache.org/jira/browse/CASSANDRA-14173. This fix is contained in the 3.11.2 release of Apache Cassandra.
Published 2018-06-28 · Modified
9.8EPSS 0.023
CVE-2021-44521
Remote code execution for scripted UDFs
Published 2022-02-11 · Modified
9.1EPSS 0.575
CVE-2025-23015
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
Published 2025-02-04 · Analyzed
8.8EPSS 0.010
CVE-2025-26467
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)
Published 2025-08-25 · Analyzed
8.8EPSS 0.005
CVE-2026-27314
Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
Published 2026-04-07 · Analyzed
8.8EPSS 0.003
CVE-2016-4970
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
Published 2017-04-13 · Modified
7.8EPSS 0.113
CVE-2023-30601
Apache Cassandra: Privilege escalation when enabling FQL/Audit logs
Published 2023-05-30 · Modified
7.8EPSS 0.003
CVE-2015-0225
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.
Published 2015-04-03 · Modified
7.5EPSS 0.066
CVE-2020-17516
Apache Cassandra versions 2.1.0 to 2.1.22, 2.2.0 to 2.2.19, 3.0.0 to 3.0.23, and 3.11.0 to 3.11.9, when using 'dc' or 'rack' internode_encryption setting, allows both encrypted and unencrypted internode connections. A misconfigured node or a malicious user can use the unencrypted connection despite not being in the same rack or dc, and bypass mutual TLS requirement.
Published 2021-02-03 · Modified
7.5EPSS 0.019
CVE-2026-32588
Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
Published 2026-04-07 · Analyzed
6.5EPSS 0.007
CVE-2019-2684
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Published 2019-04-23 · Modified
5.9EPSS 0.376
CVE-2020-13946
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.
Published 2020-09-01 · Modified
5.9EPSS 0.030
CVE-2026-27315
Apache Cassandra: cqlsh history sensitive information leak
Published 2026-04-07 · Analyzed
5.5EPSS 0.002
CVE-2025-24860
Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions
Published 2025-02-04 · Analyzed
5.4EPSS 0.011
CVE-2024-27137
Apache Cassandra: unrestricted deserialization of JMX authentication credentials
Published 2025-02-04 · Analyzed
5.3EPSS 0.003