SB2026082482 - Multiple vulnerabilities in Apache CloudStack



SB2026082482 - Multiple vulnerabilities in Apache CloudStack

Published: August 24, 2026

Security Bulletin ID SB2026082482
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 20
Exploitation vector Remote access
Highest impact Privilege escalation

Breakdown by Severity

Medium 60% Low 40%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 20 vulnerabilities.


1) Cross-site scripting (CVE-ID: CVE-2026-61399)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.

The vulnerability exists due to cross-site scripting in the UI lock user functionality when rendering insufficiently escaped output. A remote attacker can inject crafted content to execute arbitrary script in the victim's browser.


2) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-59654)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of resource after effective lifetime in scoped global configuration functionality when handling configuration operations across different management server modules and plugins. A remote attacker can trigger resource consumption to cause a denial of service.

The issue affects different modules and plugins of the management server, including Quota and Host-HA.


3) Improper Certificate Validation (CVE-ID: CVE-2026-68745)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to forge SAML responses and log in to the management server.

The vulnerability exists due to improper certificate validation in SAML authentication when processing SAML responses from a certificate-less identity provider configuration. A remote attacker can spoof the identity provider address or use a registered URL under their control to forge SAML responses and log in to the management server.

The issue affects SAML authentication when signature validation is silently skipped.


4) Improper access control (CVE-ID: CVE-2026-66797)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to create and read annotations on entities they do not own.

The vulnerability exists due to improper access control in the addAnnotation and listAnnotation APIs when processing entity UUIDs and incorrectly honoring ownership check results. A remote user can supply a target entity UUID to create and read annotations on entities they do not own.


5) Incorrect authorization (CVE-ID: CVE-2026-66722)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify project roles and permissions across unrelated domains.

The vulnerability exists due to improper authorization in ProjectRole and ProjectRolePermission CRUD operations when domain admins target projects outside their domain or subdomain. A remote user can send crafted role management requests to modify project roles and permissions across unrelated domains.

The check verifies only that the caller is a Domain Admin and does not verify whether the target project belongs to the caller's domain or subdomain.


6) Missing Authorization (CVE-ID: CVE-2026-66721)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose host tags outside the intended domain scope.

The vulnerability exists due to missing authorization in the listHostTags API when domain admins request host tag listings without domain scoping. A remote user can call the API to disclose host tags outside the intended domain scope.

By default, Domain Admins have permission to call the API.


7) Improper access control (CVE-ID: CVE-2026-65613)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose webhook delivery information and delete deliveries without authorization.

The vulnerability exists due to improper access control in the webhook module when listing and deleting deliveries. A remote user can invoke delivery management functionality to disclose webhook delivery information and delete deliveries without authorization.


8) Improper access control (CVE-ID: CVE-2026-62440)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to manipulate Kubernetes clusters across tenants.

The vulnerability exists due to improper access control in the Kubernetes Service plugin when adding and removing cluster nodes. A remote user can send crafted cluster management requests to manipulate Kubernetes clusters across tenants.


9) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-61422)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to trigger server-side requests to unintended destinations.

The vulnerability exists due to server-side request forgery in the template and ISO registration functionality when registering a template or ISO before URL validation is performed. A remote user can submit a crafted registration request to trigger server-side requests to unintended destinations.

The server makes a live HTTP HEAD or GET request for file size checks before validating the URL, but URL validation still occurs before the actual download by the Secondary Storage VM.


10) Command injection (CVE-ID: CVE-2026-61400)

CWE-ID: CWE-77 - Command injection

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary commands on system VMs and virtual routers.

The vulnerability exists due to command injection in the getDiagnosticsData and runDiagnostics functionality when processing diagnostic command input. A remote user can send crafted diagnostic requests to execute arbitrary commands on system VMs and virtual routers.

The commands run as root, or at minimum as the diagnostics-process user, and the affected APIs are restricted to Admin role accounts by default.


11) OS Command Injection (CVE-ID: CVE-2026-47359)

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary commands on the KVM hypervisor host.

The vulnerability exists due to command injection in the NAS backup provider plugin addBackupRepository and updateBackupRepository APIs when processing unsanitized backup repository mount command options. A remote user can supply crafted command options to execute arbitrary commands on the KVM hypervisor host.

Exploitation requires an operator account, and the injected commands are triggered when a backup restore is later performed.


12) Cross-site scripting (CVE-ID: CVE-2026-61398)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.

The vulnerability exists due to cross-site scripting in the UI instance reset password functionality when rendering insufficiently escaped output. A remote attacker can inject crafted content to execute arbitrary script in the victim's browser.


13) Information disclosure (CVE-ID: CVE-2026-61397)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose OAuth2 tokens across requests.

The vulnerability exists due to exposure of sensitive information in the OAuth2 authentication plugin and Google OAuth integration when handling OAuth2 requests. A remote attacker can exploit cross-request token leakage to disclose OAuth2 tokens across requests.


14) Improper privilege management (CVE-ID: CVE-2026-59799)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass the two-factor authentication disable flow.

The vulnerability exists due to improper privilege management in the two-factor authentication plugin when handling requests to disable two-factor authentication. A remote user can exploit missing privilege checks to bypass the two-factor authentication disable flow.


15) Improper access control (CVE-ID: CVE-2026-59780)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose LDAP provider configuration information.

The vulnerability exists due to improper access control in the LDAP authentication plugin listLdapConfigurations API when listing LDAP providers. A remote user can invoke the API to disclose LDAP provider configuration information.

By default, the API is available to all default roles.


16) Cleartext storage of sensitive information (CVE-ID: CVE-2026-59657)

CWE-ID: CWE-312 - Cleartext Storage of Sensitive Information

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information stored in async jobs.

The vulnerability exists due to cleartext storage of sensitive information in AsyncJob database storage when storing async job data. A local user can read stored async job data to disclose sensitive information stored in async jobs.


17) Improper access control (CVE-ID: CVE-2026-59655)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose OAuth provider client secrets.

The vulnerability exists due to improper access control in the OAuth authentication plugin when listing OAuth providers. A remote attacker can invoke provider listing functionality to disclose OAuth provider client secrets.

The issue is described as unauthenticated client-secret disclosure.


18) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-59085)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger server-side requests to unintended destinations.

The vulnerability exists due to server-side request forgery in the webhook module when processing webhook delivery requests. A remote attacker can cause the server to send crafted requests to trigger server-side requests to unintended destinations.


19) Improper access control (CVE-ID: CVE-2026-50222)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access and manipulate userdata resources across tenants.

The vulnerability exists due to improper access control in the userdata reference APIs and deleteCniConfiguration API when handling requests for userdata resources without sufficient access validation. A remote user can send crafted API requests to access and manipulate userdata resources across tenants.

The affected APIs include deleteUserData, linkUserDataToTemplate, resetUserDataForVirtualMachine, deployVirtualMachine, and updateVirtualMachine.


20) Input validation error (CVE-ID: CVE-2026-50112)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary shell commands as root on the KVM hypervisor host.

The vulnerability exists due to improper input validation in direct download, metalink, and NFS template handling when processing template registrations that reference crafted metalink files and inner URLs that are not re-validated. A remote user can register a crafted template to execute arbitrary shell commands as root on the KVM hypervisor host.

The issue is reachable via the public CloudStack API and can affect hosts running other tenants' virtual machines.


Remediation

Install update from vendor's website.