Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32588

23
FAUCET Score

CVE-2026-32588 is an authenticated denial-of-service vulnerability in Apache Cassandra versions 4.0, 4.1, and 5.0 that permits authenticated users to elevate query latencies through repeated password changes via the CQL (Cassandra Query Language) interface. This issue affects deployments across multiple Cassandra versions and requires valid user credentials to exploit. The vulnerability presents medium severity with a CVSS score of 6.5. Attack exploitation requires network access and valid authentication credentials, making the attack vector network-based with low complexity. The primary impact is availability, as successful exploitation causes elevated query latencies and potential service degradation, though confidentiality and integrity remain unaffected. There is currently no evidence of active exploitation in the wild, as indicated by the vulnerability's inactive status on the Known Exploited Vulnerabilities list. The EPSS score of 0.0008 suggests minimal probability of exploitation, placing this CVE in the lower percentile of exploited vulnerabilities. Affected organizations should prioritize upgrading to Cassandra versions 4.0.20, 4.1.11, or 5.0.7 to remediate this issue, though the low exploitation risk suggests this is not an emergency patch scenario.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0.0, < 4.0.20CPE matchmatch criteria
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*
>= 4.1.0, < 4.1.11CPE matchmatch criteria
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.0.7CPE matchmatch criteria
cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.53%
Probability of exploitation in next 30 days
EPSS Percentile
41.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0053 is in the 52nd percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

mavenpatch availablevia ghsa
Product: org.apache.cassandra:cassandra-allFixed in: 4.0.20
mavenpatch availablevia ghsa
Product: org.apache.cassandra:cassandra-allFixed in: 4.1.11
mavenpatch availablevia ghsa
Product: org.apache.cassandra:cassandra-allFixed in: 5.0.7
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

mavenGHSA-qffm-gf3j-6mvglow

Apache Cassandra has an authenticated DoS over CQL

Apr 7, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10877.html

CASSANDRA-21202: CVE-2026-32588: Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing

Apr 7, 2026

References

openwall.com / lists/oss-security/2026/04/07/9
Mailing ListThird Party Advisory
lists.apache.org / thread/2tnwjdnss378glxrsmnlzz3k53ftphrc
Mailing ListVendor Advisory