CVE-2026-65770: Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
Published Aug 20, 2026
·Updated
Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
Other sources
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Azure Managed Instance for Apache Cassandra
Microsoft Azure Managed Instance for Apache Cassandra
Event History
Aug 20, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is exploitable over a network and requires no privileges or user interaction. It allows an unauthorized attacker to execute code.
2
What is the potential impact of a successful exploit?
A successful exploit can result in remote code execution. The supplied severity metrics indicate high impact to confidentiality, integrity, and availability, with scope changed.