CVE-2025-26511: Cassandra-Lucene-Index allows bypass of Cassandra RBAC
Summary / Details Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.0-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which when successfully exploited could allow authenticated Cassandra users to remotely bypass RBAC to access data and and escalate their privileges.
Affected Versions - Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 - versions 4.1.0-1.0.0 through 4.1.8-1.0.0 when installed into Apache Cassandra version 4.x.
Required Configuration for Exploit These are the conditions required to enable exploit: 1. Cassandra 4.x 2. Vulnerable version of the Cassandra-Lucene-Index plugin configured for use 3. Data added to tables 4. Lucene index created 5. Cassandra flush has run
Mitigation/Prevention Mitigation requires dropping all Lucene indexes and stopping use of the plugin. Exploit will be possible any time the required conditions are met.
Solution Upgrade to a fixed version of the Cassandra-Lucene-Index plugin. Review users in Cassandra to validate all superuser privileges.
Other sources
Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0.0, installed into Apache Cassandra version 4.x, are susceptible to a vulnerability which when successfully exploited could allow authenticated Cassandra users to remotely bypass RBAC and escalate their privileges.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.instaclustr:cassandra-lucene-index-pluginto a version that resolves this vulnerability.Fixed in 4.1.8-1.0.1 - Upgrade
Upgrade
maven/com.instaclustr:cassandra-lucene-index-pluginto a version that resolves this vulnerability.Fixed in 4.0.17-1.0.0 - Remove
Remove
Cassandra-Lucene-Index plugin (Instaclustr fork of Stratio's Cassandra-Lucene-Index) versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.0-1.0.0 through 4.1.8-1.0.0from your environment.Drop all Lucene indexes and stop use of the Cassandra-Lucene-Index plugin on Cassandra 4.x.
- Compensating control
Review users in Apache Cassandra to validate all superuser privileges.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26511?
The severity of CVE-2025-26511 is currently classified as high due to potential exploitation risks.
How do I fix CVE-2025-26511?
To fix CVE-2025-26511, upgrade the Instaclustr Cassandra-Lucene-Index plugin to a version beyond the affected releases.
What versions are affected by CVE-2025-26511?
CVE-2025-26511 affects Instaclustr Cassandra-Lucene-Index versions 4.0-rc1-1.0.0 to 4.0.16-1.0.0 and 4.1.2-1.0.0 to 4.1.8-1.0.0, as well as Apache Cassandra 4.x.
What should I do if I am using an affected version of the Instaclustr Cassandra-Lucene-Index?
If using an affected version, immediately upgrade to a secure version to mitigate vulnerabilities.
What type of vulnerability is CVE-2025-26511?
CVE-2025-26511 is a security vulnerability that could be exploited to compromise system integrity if not addressed.