Apache Accumulo 2.1.4-2.1.5: Unauth DDoS via Remote Shutdown (Insuff Priv)
CVE-2026-62764 Published on July 17, 2026

Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions
Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver), leading to a denial of service. This issue affects Apache Accumulo 2.1.4 and 2.1.5. Users are recommended to upgrade to version 2.1.6, which fixes the issue.

Vendor Advisory Vendor Advisory NVD

Weakness Type

Improper Handling of Insufficient Privileges

The software does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.


Products Associated with CVE-2026-62764

Want to know whenever a new CVE is published for Apache Accumulo? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Accumulo: