CVE-2026-47846
Received
Received - Intake
Default Superuser Retained in Bitnami Cassandra Container Images
Publication date: 2026-06-18
Last updated on: 2026-06-18
Assigner: VMware
Description
Description
Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via the CASSANDRA_USER environment variable, the container initialization script creates the new superuser account but fails to drop the built-in cassandra account in certain scenarios. This leaves the default cassandra:cassandra superuser active as an unintended access path.
Affected versions β Container image: 4.0.x prior to 4.0.20-photon-5-r7; 4.1.x prior to 4.1.11-photon-5-r7; 5.0.x prior to 5.0.8-photon-5-r4 / 5.0.8-debian-12-r3.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| bitnami | cassandra | to 4.0.20-photon-5-r7 (exc) |
| bitnami | cassandra | to 4.1.11-photon-5-r7 (exc) |
| bitnami | cassandra | to 5.0.8-photon-5-r4 (exc) |
| bitnami | cassandra | to 5.0.8-debian-12-r3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |