Improper Authorization in Apache CloudStack - CVE-2025-66170

 

Improper Authorization in Apache CloudStack - CVE-2025-66170

Published: May 12, 2026


Vulnerability identifier: #VU131150
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66170
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to list backups from other accounts.

The vulnerability exists due to improper authorization in the CloudStack Backup plugin when handling backup listing API requests. A remote user can call specific APIs to list backups from any account in the environment to list backups from other accounts.

The issue does not expose the contents of the backups, and exploitation requires the backup plugin to be enabled.


Affected software

Apache CloudStack

How to mitigate CVE-2025-66170

Install security update from vendor's website.

Apache CloudStack - update to 4.22.0.1

External References

Related Security Bulletins