Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2806 articles · 108988 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-27315PATCHED
apache software foundation · apache cassandra

Apache Cassandra: cqlsh history sensitive information leak

Description

Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via  ~/.cassandra/cqlsh_history local file access. Users are recommended to upgrade to version 4.0.20, which fixes this issue. -- Description: Cassandra's command-line tool, cqlsh, provides a command history feature that allows users to recall previously executed commands using the up/down arrow keys. These history records are saved in the ~/.cassandra/cqlsh_history file in the user's home directory. However, cqlsh does not redact sensitive information when saving command history. This means that if a user executes operations involving passwords (such as logging in or creating users) within cqlsh, these passwords are permanently stored in cleartext in the history file on the disk.

Affected Products

VendorProductVersions
apache software foundationapache cassandramaven/org.apache.cassandra:cassandra-all: >= 4.0, < 4.0.20

References

  • https://issues.apache.org/jira/browse/CASSANDRA-21180(issue-tracking)
  • https://lists.apache.org/thread/ft77zrk2mzt8qsch4g6jqjj4901d22k3(vendor-advisory)

Related News (2 articles)

Tier C
oss-security1d ago
CVE-2026-27315: Apache Cassandra: cqlsh history sensitive information leak
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-27315 | Apache Cassandra up to 4.0.19 cqlsh History information disclosure
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
org.apache.cassandra:cassandra-all@4.0.20
CWECWE-532
PublishedApr 7, 2026
Trending Score31
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-34197EXP
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Trending: 77
HIGHCVE-2026-27314EXP
Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
Trending: 63
HIGHCVE-2026-35554
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
Trending: 40
MEDIUMCVE-2026-33227
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Classpath Directory
Trending: 29
LOWCVE-2026-32588
Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing
Trending: 29

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 7, 2026
Discovered by ZDM
Apr 7, 2026
Patch Available
Apr 7, 2026