CVE-2026-47846: Critical severity Bitnami Bitnami Cassandra container image vulnerability
Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via the CASSANDRAUSER environment variable, the container initialization script creates the new superuser account but fails to drop the built-in cassandra account in certain scenarios. This leaves the default cassandra:cassandra superuser active as an unintended access path.
Affected versions — Container image: 4.0.x prior to 4.0.20-photon-5-r7; 4.1.x prior to 4.1.11-photon-5-r7; 5.0.x prior to 5.0.8-photon-5-r4 / 5.0.8-debian-12-r3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
bitnami/cassandrato a version that resolves this vulnerability.Fixed in 4.0.20-photon-5-r7 - Upgrade
Upgrade
bitnami/cassandrato a version that resolves this vulnerability.Fixed in 4.1.11-photon-5-r7 - Upgrade
Upgrade
bitnami/cassandrato a version that resolves this vulnerability.Fixed in 5.0.8-photon-5-r4 - Upgrade
Upgrade
bitnami/cassandrato a version that resolves this vulnerability.Fixed in 5.0.8-debian-12-r3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47846?
The severity of CVE-2026-47846 is classified as critical with a score of 9.8.
What is the impact of the vulnerability CVE-2026-47846?
CVE-2026-47846 allows unauthorized access through a retained default superuser account, potentially leading to full compromise of the system.
How do I fix CVE-2026-47846?
To mitigate CVE-2026-47846, ensure that the built-in 'cassandra' user is removed from the Bitnami Cassandra container after creating a custom superuser.
Which software is affected by CVE-2026-47846?
CVE-2026-47846 affects Bitnami Cassandra container images.
When was CVE-2026-47846 published?
CVE-2026-47846 was published on June 18, 2026.