CVE-2026-32588 is an authenticated denial-of-service vulnerability in Apache Cassandra versions 4.0, 4.1, and 5.0 that permits authenticated users to elevate query latencies through repeated password changes via the CQL (Cassandra Query Language) interface. This issue affects deployments across multiple Cassandra versions and requires valid user credentials to exploit. The vulnerability presents medium severity with a CVSS score of 6.5. Attack exploitation requires network access and valid authentication credentials, making the attack vector network-based with low complexity. The primary impact is availability, as successful exploitation causes elevated query latencies and potential service degradation, though confidentiality and integrity remain unaffected. There is currently no evidence of active exploitation in the wild, as indicated by the vulnerability's inactive status on the Known Exploited Vulnerabilities list. The EPSS score of 0.0008 suggests minimal probability of exploitation, placing this CVE in the lower percentile of exploited vulnerabilities. Affected organizations should prioritize upgrading to Cassandra versions 4.0.20, 4.1.11, or 5.0.7 to remediate this issue, though the low exploitation risk suggests this is not an emergency patch scenario.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.0.20CPE matchmatch criteria | cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* | ||
>= 4.1.0, < 4.1.11CPE matchmatch criteria | cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.7CPE matchmatch criteria | cpe:2.3:a:apache:cassandra:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.