Impact
An authenticated user who lacks system permissions can remotely issue a graceful shutdown command to any of the Accumulo services, such as compaction‑coordinator, compactor, garbage collector, manager, monitor, tserver, or sserver. The vulnerability is classified as CWE‑274 and results in a denial‑of‑service condition because the services terminate rather than rejecting the request. The attack exposes no further data or execution capability beyond the induced downtime.
Affected Systems
The affected products are Apache Accumulo 2.1.4 and 2.1.5, released by the Apache Software Foundation. All installations of these versions are susceptible; upgrading to 2.1.6 mitigates the issue.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a malicious actor authenticating to the Accumulo cluster and issuing the shutdown API call; no external privilege escalation or code execution is required.
OpenCVE Enrichment