Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
The vulnerability consists of improper access control (CWE-284) in the Azure Managed Instance for Apache Cassandra service. An attacker with basic network privileges can, without user interaction and with low attack complexity, exploit this vulnerability to execute arbitrary code in the context of the service. The network attack vector and lack of requirement for high privileges significantly lower the barrier to entry for a potential exploit. The scope of the vulnerability extends beyond the directly attacked component (Scope: Changed), which may indicate the possibility of impact on other resources in the cloud environment.
An attacker can remotely execute code on infrastructure managed by Microsoft Azure, leading to complete loss of confidentiality, integrity, and availability of data stored in the service, and potentially enabling lateral movement within the cloud environment.
Apply patches available from the vendor according to the references. It is recommended to check the Microsoft Security Response Center (MSRC) at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33109 for current instructions regarding updates or workarounds. In Microsoft Azure cloud environments, managed service updates may be applied automatically — the status of your environment should be verified.
Microsoft Azure Managed Instance for Apache Cassandra — versions indicated in vendor references
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HMicrosoft Azure Managed Instance For Apache Cassandra
APPMicrosoftall versions
Related vulnerabilities
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance f...
Nieprawidłowa kontrola dostępu w Azure Managed Instance for Apache Cassandra – RCE
Nieprawidłowa kontrola dostępu w Azure Managed Instance for Apache Cassandra — privilege escalation
RCE przez deserializację niezaufanych danych w Microsoft SharePoint
Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)