Command injection in Apache CloudStack - CVE-2026-25077

 

Command injection in Apache CloudStack - CVE-2026-25077

Published: May 12, 2026


Vulnerability identifier: #VU131155
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25077
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on KVM hosts.

The vulnerability exists due to command injection in direct download template handling when processing template file names for templates downloaded to primary storage. A remote user can register a malicious template to execute arbitrary code on KVM hosts.

By default, account users are allowed to register templates for direct download for deployments using the KVM hypervisor.


Affected software

Apache CloudStack

How to mitigate CVE-2026-25077

Install security update from vendor's website.

Apache CloudStack - addressed in versions 4.20.3.0, 4.22.0.1

External References

Related Security Bulletins