CVE-2026-47846 Details
Description
Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via the CASSANDRA_USER environment variable, the container initialization script creates the new superuser account but fails to drop the built-in cassandra account in certain scenarios. This leaves the default cassandra:cassandra superuser active as an unintended access path. Affected versions — Container image: 4.0.x prior to 4.0.20-photon-5-r7; 4.1.x prior to 4.1.11-photon-5-r7; 5.0.x prior to 5.0.8-photon-5-r4 / 5.0.8-debian-12-r3.
A vulnerability exists in Bitnami Cassandra container images due to a retained default superuser account. When a custom administrator account is set using the CASSANDRA_USER environment variable, the initialization script creates the new superuser but may not remove the default cassandra account in some cases. This oversight keeps the cassandra:cassandra superuser active, providing an unintended access route. Remote attackers who know the default credentials can authenticate as a superuser, bypassing the intended account replacement. The vulnerability affects Bitnami Cassandra container images in versions 4.0.x prior to 4.0.20-photon-5-r7, 4.1.x prior to 4.1.11-photon-5-r7, and 5.0.x prior to 5.0.8-photon-5-r4 or 5.0.8-debian-12-r3.
Users should upgrade to a fixed Bitnami Cassandra container image version (4.0.20-photon-5-r7, 4.1.11-photon-5-r7, or 5.0.8-photon-5-r4 / 5.0.8-debian-12-r3). Those on end-of-life branches should migrate to a supported branch. As a temporary measure, the built-in cassandra user can be manually dropped via the CQL shell after deployment. Additionally, network access to the Cassandra CQL port should be restricted to trusted networks using firewall rules or Kubernetes NetworkPolicies.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bitnami/containers/security/advisories/GHSA-8q3j-37vg-8fc2 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |