Executive brief
Azure Managed Instance for Apache Cassandra is a database service used to run Cassandra workloads in Azure. An argument injection vulnerability allows an unauthenticated attacker to execute arbitrary code remotely on the service, potentially leading to complete compromise of data and operations.
Technical details
The vulnerability is an argument injection flaw (CWE-88) in improper neutralization of argument delimiters in a command. An unauthenticated attacker with network access can inject malicious arguments into command execution, bypassing intended restrictions and achieving remote code execution. The attack requires no user interaction or pre-existing authentication. Exploitation allows full system compromise including arbitrary command execution with the service's privileges.
Affected products
- Microsoft Azure Managed Instance for Apache Cassandra <UNKNOWN>
Timeline
- 2026-08-20: disclosed