{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-03T14:18:44.843","vulnerabilities":[{"cve":{"id":"CVE-2025-26467","sourceIdentifier":"security@apache.org","published":"2025-08-25T14:15:30.103","lastModified":"2025-08-26T21:14:41.723","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on affected versions should review data access rules for potential breaches.\n\n\n\nThis issue affects Apache Cassandra 3.0.30, 3.11.17, 4.0.16, 4.1.7, 5.0.2, but this advisory is only for 4.0.16 because the fix to CVE-2025-23015 was incorrectly applied to 4.0.16, so that version is still affected.\n\nUsers in the 4.0 series are recommended to upgrade to version 4.0.17 which fixes the issue. Users from 3.0, 3.11, 4.1 and 5.0 series should follow recommendation from CVE-2025-23015."},{"lang":"es","value":"Vulnerabilidad de privilegios definidos con acciones inseguras en Apache Cassandra. Un usuario con permiso MODIFICAR en TODOS LOS ESPACIOS DE TECLAS puede escalar privilegios a superusuario dentro de un clúster de Cassandra objetivo mediante acciones inseguras en un recurso del sistema. Los operadores que otorgan permiso MODIFICAR datos en todos los espacios de claves de las versiones afectadas deben revisar las reglas de acceso a datos para detectar posibles infracciones. Este problema afecta a Apache Cassandra 3.0.30, 3.11.17, 4.0.16, 4.1.7 y 5.0.2, pero este aviso solo aplica a la versión 4.0.16 porque la corrección a CVE-2025-23015 se aplicó incorrectamente a la 4.0.16, por lo que dicha versión sigue afectada. Se recomienda a los usuarios de la serie 4.0 actualizar a la versión 4.0.17, que corrige el problema. Los usuarios de las series 3.0, 3.11, 4.1 y 5.0 deben seguir la recomendación de CVE-2025-23015."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-267"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndExcluding":"3.0.31","matchCriteriaId":"7EBD1031-1C25-4CAC-B773-6947C69DB7FB"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*","versionStartIncluding":"3.11.0","versionEndExcluding":"3.11.18","matchCriteriaId":"B1A7CA11-3152-459B-ABF3-33A6186205AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.0.17","matchCriteriaId":"FF9E8816-7D3F-427F-A2A4-30256F19C0CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.0","versionEndExcluding":"4.1.8","matchCriteriaId":"B436C4E3-A38B-42E4-AFF4-C057BE7E156C"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.0.3","matchCriteriaId":"7BFBF10F-8408-495D-99E6-AE122CDD87CC"}]}]}],"references":[{"url":"https://lists.apache.org/thread/xxj36rr4d6mzyqpld05dn8b9951hfpz7","source":"security@apache.org","tags":["Mailing List","Vendor Advisory"]}]}}]}