Apache Accumulo 2.1.4-2.1.5: Unauth DDoS via Remote Shutdown (Insuff Priv)
CVE-2026-62764 Published on July 17, 2026
Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo.
An authenticated, but low-privileged user without system permissions may
issue a remote command to gracefully shutdown system components
(compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver),
leading to a denial of service.
This issue affects Apache Accumulo 2.1.4 and 2.1.5.
Users are recommended to upgrade to version 2.1.6, which fixes the issue.
Weakness Type
Improper Handling of Insufficient Privileges
The software does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.
Products Associated with CVE-2026-62764
Want to know whenever a new CVE is published for Apache Accumulo? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Accumulo:- Version 2.1.4, <= 2.1.5 is affected.