A vulnerability classified as critical has been found in Instaclustr Cassandra-Lucene-Index plugin up to 4.0.16-1.0.0/4.1.8-1.0.0. Affected is an unknown function of the component RBAC. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is traded as CVE-2025-26511. It is possible to launch the attack remotely. There is no exploit available.