CVE-2026-32588
published 2026-04-07CVE-2026-32588: Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users are…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.53%
41.5th percentile
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cassandra | >= 4.0.0 < 4.0.20 | 4.0.20 |
| apache | cassandra | >= 4.1.0 < 4.1.11 | 4.1.11 |
| apache | cassandra | >= 5.0.0 < 5.0.7 | 5.0.7 |
| apache_software_foundation | apache_cassandra | 4.0 – 4.0.19 | — |
| apache_software_foundation | apache_cassandra | 4.1 – 4.1.10 | — |
| apache_software_foundation | apache_cassandra | 5.0 – 5.0.6 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
vendor_redhat·2026-04-07·CVSS 6.5
CVE-2026-32588 [MEDIUM] CWE-770 Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
A flaw was found in Apache Cassandra. An authenticated user can exploit this vulnerability by repeatedly changing their password over the Cassandra Query Language (CQL). This action can significantly increase query latencies, leading to a Denial of Service (DoS) for the system.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: cassandra-all (Red Hat Data Grid 8) - Fix deferred
Package: cassandra-all (Red Hat Fuse 7) - Fix deferred
Package: cassandra-all (Red Hat JBoss Enterprise Application Platform 7
GHSA
Apache Cassandra has an authenticated DoS over CQL
ghsa·2026-04-07
CVE-2026-32588 [LOW] CWE-400 Apache Cassandra has an authenticated DoS over CQL
Apache Cassandra has an authenticated DoS over CQL
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
OSV
Apache Cassandra has an authenticated DoS over CQL
osv·2026-04-07
CVE-2026-32588 [LOW] Apache Cassandra has an authenticated DoS over CQL
Apache Cassandra has an authenticated DoS over CQL
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-32588 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-32588 [MEDIUM] CVE-2026-32588 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32588 :
Apache Cassandra vulnerability analysis and mitigation
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
Source : NVD
## 6.5
Score
Published April 7, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Apache Cassandra
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.apache.cassandra:cassandra-all
cpe:2.3:a:apache:cassandra
Sources
NVD
Maven Severity LOW Has Fix Added at: Apr 09, 2026
Linux Se
Wiz
CVE-2026-27315 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-27315 [HIGH] CVE-2026-27315 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27315 :
Apache Cassandra vulnerability analysis and mitigation
Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via ~/.cassandra/cqlsh_history local file access.
Users are recommended to upgrade to version 4.0.20, which fixes this issue.
--
Description: Cassandra's command-line tool, cqlsh, provides a command history feature that allows users to recall previously executed commands using the up/down arrow keys. These history records are saved in the ~/.cassandra/cqlsh_history file in the user's home directory.
However, cqlsh does not redact sensitive information when saving command history. This means that if a user executes operations involving passwords (such as loggi
Wiz
CVE-2026-27314 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-27314 [MEDIUM] CVE-2026-27314 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-27314 :
Apache Cassandra vulnerability analysis and mitigation
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role,
including a superuser role, and authenticate as that role via ADD IDENTITY.
Users are recommended to upgrade to version 5.0.7+, which fixes this issue.
Source : NVD
## 8.8
Score
Published April 7, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Apache Cassandra
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:apa
Bugzilla
CVE-2026-32588 log4j: Apache Cassandra: Denial of Service via repeated password changes [fedora-all]
bugzilla·2026-04-08·CVSS 6.5
CVE-2026-32588 [MEDIUM] CVE-2026-32588 log4j: Apache Cassandra: Denial of Service via repeated password changes [fedora-all]
CVE-2026-32588 log4j: Apache Cassandra: Denial of Service via repeated password changes [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-32588 Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
bugzilla·2026-04-07·CVSS 6.5
CVE-2026-32588 [MEDIUM] CVE-2026-32588 Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
CVE-2026-32588 Apache Cassandra: Apache Cassandra: Denial of Service via repeated password changes
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
2026-04-07
Published