# CVE-2026-62764

## Summary

- **CVE ID:** CVE-2026-62764
- **Severity:** MEDIUM
- **CVSS Score:** 5.7 (CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Green)
- **CWE:** CWE-274
- **Published:** Jul 17, 2026
- **Last Modified:** Jul 17, 2026

## Description

Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo.
An authenticated, but low-privileged user without system permissions may
issue a remote command to gracefully shutdown system components
(compaction-coordinator, compactor, gc, manager, monitor, tserver, or sserver),
leading to a denial of service.

This issue affects Apache Accumulo 2.1.4 and 2.1.5.

Users are recommended to upgrade to version 2.1.6, which fixes the issue.

## Affected Products

- Apache Software Foundation — Apache Accumulo (2.1.4)

## References

- [CNA](https://github.com/apache/accumulo/issues/6478)
- [CNA](https://accumulo.apache.org/release/accumulo-2.1.6/)
- [CNA](https://accumulo.apache.org/downloads/)
- [CNA](https://lists.apache.org/thread/qclg736k93oqn4qrpw9wxjbb3jhn6gm1)
- [CVE](http://www.openwall.com/lists/oss-security/2026/07/17/6)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.47%
- **EPSS Percentile:** 39.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._