https://seclists.org/oss-sec/2026/q2/33: CVE-2026-27315: Apache Cassandra: cqlsh history sensitive information leak
Published Apr 7, 2026
·Updated
Affected Software
1 affected component
Apache Cassandra>=4.0<=4.0.19
Frequently Asked Questions
1
What is the severity of CVE-2026-27315?
The severity of CVE-2026-27315 is categorized as low.
2
What versions of Apache Cassandra are affected by CVE-2026-27315?
Apache Cassandra versions 4.0 through 4.0.19 are affected by CVE-2026-27315.
3
What information is leaked by CVE-2026-27315?
CVE-2026-27315 allows access to sensitive information such as passwords from the cqlsh command history.
4
How do I mitigate CVE-2026-27315?
To mitigate CVE-2026-27315, ensure to clear or secure the ~/.cassandra/cqlsh_history file to prevent unauthorized access.
5
Is there a patch available for CVE-2026-27315?
As of the publication date, there were no specific patches released for CVE-2026-27315, but it is recommended to follow best practices for securing sensitive data.