CVE-2026-27314: Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
Published Apr 7, 2026
·Updated
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY.
Users are recommended to upgrade to version 5.0.7+, which fixes this issue.
Affected Software
2 affected componentsFixes available
maven/org.apache.cassandra:cassandra-all>=5.0-alpha1<5.0.7
5.0.7
Apache Cassandra>=5.0.0<5.0.7
Event History
Apr 7, 2026
CVE Published
via MITRE·04:33 PM
Data Sourced
via MITRE·04:33 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
Affected Software
Advisory Published
via GitHub·06:31 PM
Data Sourced
via GitHub·06:31 PM
DescriptionSeverityWeaknessAffected Software