First published: Thu Feb 13 2025(Updated: )
**Summary / Details** Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.0-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which when successfully exploited could allow authenticated Cassandra users to remotely bypass RBAC to access data and and escalate their privileges. **Affected Versions** - Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 - versions 4.1.0-1.0.0 through 4.1.8-1.0.0 when installed into Apache Cassandra version 4.x. **Required Configuration for Exploit** These are the conditions required to enable exploit: 1. Cassandra 4.x 2. Vulnerable version of the Cassandra-Lucene-Index plugin configured for use 3. Data added to tables 4. Lucene index created 5. Cassandra flush has run **Mitigation/Prevention** Mitigation requires dropping all Lucene indexes and stopping use of the plugin. Exploit will be possible any time the required conditions are met. **Solution** Upgrade to a fixed version of the Cassandra-Lucene-Index plugin. Review users in Cassandra to validate all superuser privileges.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Cassandra | >=4.0-rc1-1.0.0<=4.0.16-1.0.0>=4.1.2-1.0.0<=4.1.8-1.0.0 | |
Apache Cassandra | >=4.x | |
maven/com.instaclustr:cassandra-lucene-index-plugin | >=4.1.0-1.0.0<4.1.8-1.0.1 | 4.1.8-1.0.1 |
maven/com.instaclustr:cassandra-lucene-index-plugin | >=4.0-rc1-1.0.0<4.0.17-1.0.0 | 4.0.17-1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-26511 is currently classified as high due to potential exploitation risks.
To fix CVE-2025-26511, upgrade the Instaclustr Cassandra-Lucene-Index plugin to a version beyond the affected releases.
CVE-2025-26511 affects Instaclustr Cassandra-Lucene-Index versions 4.0-rc1-1.0.0 to 4.0.16-1.0.0 and 4.1.2-1.0.0 to 4.1.8-1.0.0, as well as Apache Cassandra 4.x.
If using an affected version, immediately upgrade to a secure version to mitigate vulnerabilities.
CVE-2025-26511 is a security vulnerability that could be exploited to compromise system integrity if not addressed.