Description
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
Published: 2026-08-20
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of argument delimiters in shell commands executed by Microsoft Azure Managed Instance for Apache Cassandra. An attacker can inject arbitrary arguments that are passed directly to the underlying command line, allowing execution of arbitrary code. The resulting remote code execution gives the attacker full control over the instance and its data.

Affected Systems

The affected product is Microsoft Azure Managed Instance for Apache Cassandra. No specific version information is provided in the advisory, so all current releases of this service that have not been patched are potentially vulnerable.

Risk and Exploitability

The CVSS score of 10 indicates the maximum severity of a security flaw. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted requests over the network to the managed instance; once network access is achieved, the argument injection allows arbitrary commands to run without authentication, making exploitation straightforward.

Generated by OpenCVE AI on August 21, 2026 at 00:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Azure Managed Instance for Apache Cassandra patch provided by Microsoft.
  • Limit inbound traffic to the instance by applying network security groups or firewall rules that permit only trusted networks.
  • After updates or restrictions are in place, monitor activity logs for unexpected command executions and verify that no insecure command paths remain.

Generated by OpenCVE AI on August 21, 2026 at 00:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:azure_managed_instance_for_apache_cassandra:-:*:*:*:*:*:*:*

Fri, 21 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
Title Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft azure Managed Instance For Apache Cassandra
Weaknesses CWE-88
CPEs cpe:2.3:a:microsoft:azure_managed_instance_for_apache_cassandra:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Managed Instance For Apache Cassandra
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Managed Instance For Apache Cassandra
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:38:33.138Z

Reserved: 2026-07-22T21:30:09.118Z

Link: CVE-2026-65770

cve-icon Vulnrichment

Updated: 2026-08-21T14:25:20.354Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:17:52.010

Modified: 2026-08-25T16:04:21.670

Link: CVE-2026-65770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T00:45:06Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')