{"schema_version": "1.6.1", "id": "CVE-2026-62764", "summary": "A user can trigger a graceful shutdown of services without the relevant system permissions", "details": "Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo.\nAn authenticated, but low-privileged user without system permissions may\nissue a remote command to gracefully shutdown system components\n(compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver),\nleading to a denial of service.\n\nThis issue affects Apache Accumulo 2.1.4 and 2.1.5.\n\nUsers are recommended to upgrade to version 2.1.6, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "2.1.4"}, {"last_affected": "2.1.4"}]}]}], "references": [{"type": "WEB", "url": "https://github.com/apache/accumulo/issues/6478"}, {"type": "WEB", "url": "https://accumulo.apache.org/release/accumulo-2.1.6/"}, {"type": "WEB", "url": "https://accumulo.apache.org/downloads/"}, {"type": "WEB", "url": "https://lists.apache.org/thread/qclg736k93oqn4qrpw9wxjbb3jhn6gm1"}]}