Improper access control in Apache CloudStack - CVE-2025-59454
Published: November 28, 2025
Apache CloudStack
Detailed vulnerability description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improper access restrictions within the following API methods: createNetworkACL, listNetworkACLs, listResourceDetails, listVirtualMachinesUsageHistory, and listVolumesUsageHistory. A remote authenticated user can send a specially crafted HTTP request and gain access to sensitive information.